MFH: r460336

Add patch and fix CVE-2017-15132

Add upstream patch to fix CVE-2017-15132, memory leak in the log in process
that can cause memory exhaustion.

PR:		225446
Submitted by:	Vladimir Krstulja
Approved by:	adamw (maintainer), swills (ports-secteam)
Security:	92b8b284-a3a2-41b1-956c-f9cf8b74f500

Approved by:	ports-secteam (implicit)
This commit is contained in:
Niclas Zeising 2018-01-29 21:04:37 +00:00
parent c08622c31f
commit a085096f6a
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/branches/2018Q1/; revision=460337
2 changed files with 11 additions and 1 deletions

View file

@ -13,7 +13,7 @@
PORTNAME= dovecot
PORTVERSION= 2.2.33.2
PORTREVISION= 2
PORTREVISION= 3
CATEGORIES= mail ipv6
MASTER_SITES= https://www.dovecot.org/releases/2.2/

View file

@ -0,0 +1,10 @@
--- src/lib-auth/auth-client-request.c.orig 2017-10-05 17:10:44 UTC
+++ src/lib-auth/auth-client-request.c
@@ -180,6 +180,7 @@ void auth_client_request_abort(struct auth_client_requ
auth_client_send_cancel(request->conn->client, request->id);
call_callback(request, AUTH_REQUEST_STATUS_ABORT, NULL, NULL);
+ pool_unref(&request->pool);
}
unsigned int auth_client_request_get_id(struct auth_client_request *request)