Marcus Rueckert
e5278c2201
- update to 2.3.11.3 and pigeonhole to 0.5.11 Dovecot 2.3.11.3 - pop3-login: Login didn't handle commands in multiple IP packets properly. This mainly affected large XCLIENT commands or a large SASL initial response parameter in the AUTH command. - pop3: pop3_deleted_flag setting was broken, causing: Panic: file seq-range-array.c: line 472 (seq_range_array_invert): assertion failed: (range[count-1].seq2 <= max_seq) Dovecot 2.3.11.2 - auth: Lua passdb/userdb leaks stack elements per call, eventually causing the stack to become too deep and crashing the auth or auth-worker process. - lib-mail: v2.3.11 regression: MIME parts not returned correctly by Dovecot MIME parser. - pop3-login: Login would fail with "Input buffer full" if the initial response for SASL was too long. Dovecot 2.3.11 * CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. * CVE-2020-12673: Dovecot's NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. * CVE-2020-10967: lmtp/submission: Issuing the RCPT command with an address that has the empty quoted string as local-part causes the lmtp service to crash. * CVE-2020-12674: Dovecot's RPA mechanism implementation accepts zero-length message, which leads to assert-crash later on. * Events: Fix inconsistency in events. See event documentation in https://doc.dovecot.org. OBS-URL: https://build.opensuse.org/request/show/826219 OBS-URL: https://build.opensuse.org/package/show/server:mail/dovecot23?expand=0&rev=76 |
||
---|---|---|
.gitattributes | ||
.gitignore | ||
allow-tls1.3-only.patch | ||
dovecot23.changes | ||
dovecot23.keyring | ||
dovecot23.spec | ||
dovecot-2.0.configfiles | ||
dovecot-2.1-pigeonhole.configfiles | ||
dovecot-2.1.configfiles | ||
dovecot-2.2-pigeonhole.configfiles | ||
dovecot-2.2.configfiles | ||
dovecot-2.3-pigeonhole-0.5.11.tar.gz | ||
dovecot-2.3-pigeonhole-0.5.11.tar.gz.sig | ||
dovecot-2.3-pigeonhole.configfiles | ||
dovecot-2.3.0-better_ssl_defaults.patch | ||
dovecot-2.3.0-dont_use_etc_ssl_certs.patch | ||
dovecot-2.3.11.3.tar.gz | ||
dovecot-2.3.11.3.tar.gz.sig | ||
dovecot-2.3.configfiles | ||
dovecot-rpmlintrc |