pkgsrc/mail/dovecot2
taca c6d08e3b4c mail/dovecot2: update to 2.3.10.1
Update dovecot2 to 2.3.10.1.


v2.3.10.1  2020-05-18  Aki Tuomi <aki.tuomi@open-xchange.com>

- CVE-2020-10957: lmtp/submission: A client can crash the server by
  sending a NOOP command with an invalid string parameter. This occurs
  particularly for a parameter that doesn't start with a double quote.
  This applies to all SMTP services, including submission-login, which
  makes it possible to crash the submission service without
  authentication.
- CVE-2020-10958: lmtp/submission: Sending many invalid or unknown
  commands can cause the server to access freed memory, which can lead
  to a server crash. This happens when the server closes the connection
  with a "421 Too many invalid commands" error. The bad command limit
  depends on the service (lmtp or submission) and varies between 10 to
  20 bad commands.
- CVE-2020-10967: lmtp/submission: Issuing the RCPT command with an
  address that has the empty quoted string as local-part causes the lmtp
  service to crash.
2020-05-18 14:20:46 +00:00
..
files
patches mail/dovecot2: update to 2.3.7.1 2019-07-23 15:11:24 +00:00
buildlink3.mk *: Recursive revision bump for openssl 1.1.1. 2020-01-18 21:48:10 +00:00
DESCR
distinfo mail/dovecot2: update to 2.3.10.1 2020-05-18 14:20:46 +00:00
Makefile dovecot2: updated to 2.3.10 2020-03-15 22:52:04 +00:00
Makefile.common mail/dovecot2: update to 2.3.10.1 2020-05-18 14:20:46 +00:00
options.mk *: Remove obsolete BUILDLINK_API_DEPENDS.openssl. 2020-01-25 10:45:10 +00:00
PLIST dovecot2: updated to 2.3.10 2020-03-15 22:52:04 +00:00