1
0
mirror of https://git.FreeBSD.org/ports.git synced 2024-12-04 01:48:54 +00:00
freebsd-ports/mail/dovecot
Larry Rosenman 6acbbd56d3 mail/dovecot: Upgrade to 2.3.10.1, fixing multiple vulnerabilities.
- CVE-2020-10957: lmtp/submission: A client can crash the server by
  sending a NOOP command with an invalid string parameter. This occurs
  particularly for a parameter that doesn't start with a double quote.
  This applies to all SMTP services, including submission-login, which
  makes it possible to crash the submission service without
  authentication.
- CVE-2020-10958: lmtp/submission: Sending many invalid or unknown
  commands can cause the server to access freed memory, which can lead
  to a server crash. This happens when the server closes the connection
  with a "421 Too many invalid commands" error. The bad command limit
  depends on the service (lmtp or submission) and varies between 10 to
  20 bad commands.
- CVE-2020-10967: lmtp/submission: Issuing the RCPT command with an
  address that has the empty quoted string as local-part causes the
  lmtp service to crash.

Clean up some REINPLACE warnings whilst we're here.

MFH:		2020Q2
Security:	37d106a8-15a4-483e-8247-fcb68b16eaf8
Security:	CVE-2020-10957
Security:	CVE-2020-10958
Security:	CVE-2020-10967
2020-05-18 19:28:52 +00:00
..
files mail/dovecot: use libexttextcat for lucene. 2020-03-23 22:07:58 +00:00
distinfo mail/dovecot: Upgrade to 2.3.10.1, fixing multiple vulnerabilities. 2020-05-18 19:28:52 +00:00
Makefile mail/dovecot: Upgrade to 2.3.10.1, fixing multiple vulnerabilities. 2020-05-18 19:28:52 +00:00
pkg-descr
pkg-plist mail/dovecot: update to 2.3.10. 2020-03-06 19:16:54 +00:00