notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
All times are UTC
Ukraine
non port: mail/dovecot/files/patch-src_doveadm_Makefile.am
SVNWeb

Number of commits found: 2

Wed, 28 Feb 2018
[ 23:12 adamw search for other commits by this committer ] Original commit   Revision:463271
Update dovecot to 2.2.34, and bump pigeonhole.

 * CVE-2017-15130: TLS SNI config lookups may lead to excessive
   memory usage, causing imap-login/pop3-login VSZ limit to be reached
   and the process restarted. This happens only if Dovecot config has
   local_name { } or local { } configuration blocks and attacker uses
   randomly generated SNI servernames.
 * CVE-2017-14461: Parsing invalid email addresses may cause a crash or
   leak memory contents to attacker. For example, these memory contents
   might contain parts of an email from another user if the same imap
   process is reused for multiple users. First discovered by Aleksandar
   Nikolic of Cisco Talos. Independently also discovered by "flxflndy"
   via HackerOne.
 * CVE-2017-15132: Aborted SASL authentication leaks memory in login
   process.
(Only the first 15 lines of the commit message are shown above View all of this commit message)
Wed, 11 Oct 2017
[ 17:47 ler search for other commits by this committer ] Original commit   Revision:451766
mail/dovecot: fix a parallel build issue.

Reported by:	leres
Obtained
from:	https://github.com/dovecot/core/commit/b200bc3875fa06d42c8619865cc306c3297fcacc
(part)

Number of commits found: 2