be1de0964096d85759af7e3a9bf028b57540bc1b81723ad4b6379243fb7c4781
- update to 2.3.4.1 (boo#1123022) * CVE-2019-3814: If imap/pop3/managesieve/submission client has trusted certificate with missing username field (ssl_cert_username_field), under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing. * ssl_cert_username_field setting was ignored with external SMTP AUTH, because none of the MTAs (Postfix, Exim) currently send the cert_username field. This may have allowed users with trusted certificate to specify any username in the authentication. This bug didn't affect Dovecot's Submission service. OBS-URL: https://build.opensuse.org/request/show/671912 OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/dovecot23?expand=0&rev=15
Description
No description provided
Languages
Standard ML
100%