/[ports]
ViewVC logotype

Revision 492245


Jump to revision: Previous Next
Author: ler
Date: Tue Feb 5 14:50:38 2019 UTC (5 years, 5 months ago)
Changed paths: 2
Log Message:
mail/dovecot: upgrade to 2.3.4.1

    * CVE-2019-3814: If imap/pop3/managesieve/submission client has
      trusted certificate with missing username field
      (ssl_cert_username_field), under some configurations Dovecot
      mistakenly trusts the username provided via authentication instead
      of failing.
    * ssl_cert_username_field setting was ignored with external SMTP AUTH,
      because none of the MTAs (Postfix, Exim) currently send the
      cert_username field. This may have allowed users with trusted
      certificate to specify any username in the authentication. This bug
      didn't affect Dovecot's Submission service.

PR:		235523
Submitted by:	pascal.christen@hostpoint.ch
MFH:		2019Q1
Security:	1340fcc1-2953-11e9-bc44-a4badb296695
Security:	CVE-2019-3814


Changed paths

Path Details
Directoryhead/mail/dovecot/Makefile modified , text changed
Directoryhead/mail/dovecot/distinfo modified , text changed

  ViewVC Help
Powered by ViewVC 1.1.27