1
0
mirror of https://git.FreeBSD.org/ports.git synced 2024-12-02 01:20:54 +00:00
freebsd-ports/mail/dovecot
Larry Rosenman a434efa6bf mail/dovecot: upgrade to 2.3.4.1
* CVE-2019-3814: If imap/pop3/managesieve/submission client has
      trusted certificate with missing username field
      (ssl_cert_username_field), under some configurations Dovecot
      mistakenly trusts the username provided via authentication instead
      of failing.
    * ssl_cert_username_field setting was ignored with external SMTP AUTH,
      because none of the MTAs (Postfix, Exim) currently send the
      cert_username field. This may have allowed users with trusted
      certificate to specify any username in the authentication. This bug
      didn't affect Dovecot's Submission service.

PR:		235523
Submitted by:	pascal.christen@hostpoint.ch
MFH:		2019Q1
Security:	1340fcc1-2953-11e9-bc44-a4badb296695
Security:	CVE-2019-3814
2019-02-05 14:50:38 +00:00
..
files mail/dovecot: Fix previous commit. 2019-01-06 17:55:58 +00:00
distinfo mail/dovecot: upgrade to 2.3.4.1 2019-02-05 14:50:38 +00:00
Makefile mail/dovecot: upgrade to 2.3.4.1 2019-02-05 14:50:38 +00:00
pkg-descr Rename dovecot2/dovecot2-pigeonhole to dovecot/dovecot-pigeonhole. 2017-08-07 21:44:00 +00:00
pkg-plist mail/dovecot: add option to support libsodium 2018-12-04 11:33:06 +00:00