Path to this page:
Subject: CVS commit: pkgsrc/mail/dovecot2
From: Takahiro Kambe
Date: 2019-02-06 02:41:28
Message id: 20190206014128.E057BFB16@cvs.NetBSD.org
Log Message:
mail/dovecot2: update to 2.3.4.1
v2.3.4.1 2019-02-05 Aki Tuomi <aki.tuomi@open-xchange.com>
* CVE-2019-3814: If imap/pop3/managesieve/submission client has
trusted certificate with missing username field
(ssl_cert_username_field), under some configurations Dovecot
mistakenly trusts the username provided via authentication instead
of failing.
* ssl_cert_username_field setting was ignored with external SMTP AUTH,
because none of the MTAs (Postfix, Exim) currently send the
cert_username field. This may have allowed users with trusted
certificate to specify any username in the authentication. This bug
didn't affect Dovecot's Submission service.
Files: