be1de09640
- update to 2.3.4.1 (boo#1123022) * CVE-2019-3814: If imap/pop3/managesieve/submission client has trusted certificate with missing username field (ssl_cert_username_field), under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing. * ssl_cert_username_field setting was ignored with external SMTP AUTH, because none of the MTAs (Postfix, Exim) currently send the cert_username field. This may have allowed users with trusted certificate to specify any username in the authentication. This bug didn't affect Dovecot's Submission service. OBS-URL: https://build.opensuse.org/request/show/671912 OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/dovecot23?expand=0&rev=15 |
||
---|---|---|
.gitattributes | ||
.gitignore | ||
3c5101ffdd2a8115e03ed7180d53578765dea4c9.patch | ||
10048229...de42b54a.patch | ||
dovecot23.changes | ||
dovecot23.keyring | ||
dovecot23.spec | ||
dovecot-2.0.configfiles | ||
dovecot-2.1-pigeonhole.configfiles | ||
dovecot-2.1.configfiles | ||
dovecot-2.2-pigeonhole.configfiles | ||
dovecot-2.2.configfiles | ||
dovecot-2.3-pigeonhole-0.5.4.tar.gz | ||
dovecot-2.3-pigeonhole-0.5.4.tar.gz.sig | ||
dovecot-2.3-pigeonhole.configfiles | ||
dovecot-2.3.0-better_ssl_defaults.patch | ||
dovecot-2.3.0-dont_use_etc_ssl_certs.patch | ||
dovecot-2.3.4.1.tar.gz | ||
dovecot-2.3.4.1.tar.gz.sig | ||
dovecot-2.3.configfiles | ||
dovecot-rpmlintrc |