pkgsrc/mail/dovecot2
taca 01e5879941 mail/dovecot2: update to 2.3.0.1
Small patch release to fix the worst bugs in v2.3.0. v2.3.1 is coming in about a month with a lot more changes.

 * CVE-2017-15130: TLS SNI config lookups may lead to excessive
   memory usage, causing imap-login/pop3-login VSZ limit to be reached
   and the process restarted. This happens only if Dovecot config has
   local_name { } or local { } configuration blocks and attacker uses
   randomly generated SNI servernames.
 * CVE-2017-14461: Parsing invalid email addresses may cause a crash or
   leak memory contents to attacker. For example, these memory contents
   might contain parts of an email from another user if the same imap
   process is reused for multiple users. First discovered by Aleksandar
   Nikolic of Cisco Talos. Independently also discovered by "flxflndy"
   via HackerOne.
 * CVE-2017-15132: Aborted SASL authentication leaks memory in login
   process.
 * Linux: Core dumping is no longer enabled by default via
   PR_SET_DUMPABLE, because this may allow attackers to bypass
   chroot/group restrictions. Found by cPanel Security Team. Nowadays
   core dumps can be safely enabled by using "sysctl -w
   fs.suid_dumpable=2". If the old behaviour is wanted, it can still be
   enabled by setting:
   import_environment=$import_environment PR_SET_DUMPABLE=1
 - imap-login with SSL/TLS connections may end up in infinite loop
2018-03-01 11:13:14 +00:00
..
files Remove the stability entity, it has no meaning outside of an official context. 2016-06-08 10:16:50 +00:00
patches dovecot2: remove now redundant patch. 2018-01-04 00:22:02 +00:00
buildlink3.mk mail/dovecot2: bump ABI dependency to 2.3.0 for dovecot2-pigeonhole. 2018-01-08 13:03:15 +00:00
DESCR
distinfo mail/dovecot2: update to 2.3.0.1 2018-03-01 11:13:14 +00:00
Makefile Move including options.mk to Makefile.common, the plugins do a full build 2017-05-15 12:31:10 +00:00
Makefile.common mail/dovecot2: update to 2.3.0.1 2018-03-01 11:13:14 +00:00
Makefile.plugin dovecot2: update to 2.2.33.1 2017-10-12 10:34:28 +00:00
MESSAGE
options.mk Split off dovecot2-{gssapi,ldap,mysql,pgsql,sqlite} as separate 2016-07-18 15:03:05 +00:00
PLIST mail/dovecot2: update to 2.3.0.1 2018-03-01 11:13:14 +00:00