From mboxrd@z Thu Jan 1 00:00:00 1970 From: Peter Korsgaard Date: Fri, 22 May 2020 21:02:07 +0200 Subject: [Buildroot] [PATCH 2/2] package/dovecot: security bump to version 2.3.10.1 In-Reply-To: <20200522135808.312867-2-fontaine.fabrice@gmail.com> (Fabrice Fontaine's message of "Fri, 22 May 2020 15:58:08 +0200") References: <20200522135808.312867-1-fontaine.fabrice@gmail.com> <20200522135808.312867-2-fontaine.fabrice@gmail.com> Message-ID: <87sgfrkd3k.fsf@dell.be.48ers.dk> List-Id: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: buildroot@busybox.net >>>>> "Fabrice" == Fabrice Fontaine writes: > - Fix CVE-2020-10957: In Dovecot before 2.3.10.1, unauthenticated > sending of malformed parameters to a NOOP command causes a NULL > Pointer Dereference and crash in submission-login, submission, or > lmtp. > - Fix CVE-2020-10958: In Dovecot before 2.3.10.1, a crafted SMTP/LMTP > message triggers an unauthenticated use-after-free bug in > submission-login, submission, or lmtp, and can lead to a crash under > circumstances involving many newlines after a command. > - Fix CVE-2020-10967: In Dovecot before 2.3.10.1, remote > unauthenticated attackers can crash the lmtp or submission process by > sending mail with an empty localpart. > - Drop first patch (already in version) and so autoreconf > - Update indentation in hash file (two spaces) > Signed-off-by: Fabrice Fontaine Committed, thanks. -- Bye, Peter Korsgaard