SUSE-SU-2019:2514-1
Dashboard / Vulnerabilities / SUSE-SU-2019:2514-1
SUSE-SU-2019:2514-1
Summary: Security update for dovecot23
Details: This update for dovecot23 fixes the following issues: - CVE-2019-11500: Fixed the NUL byte handling in IMAP and ManageSieve protocol parsers. (bsc#1145559) - CVE-2019-11499: Fixed a vulnerability where the submission-login would crash over a TLS secured channel (bsc#1133625). - CVE-2019-11494: Fixed a denial of service if the authentication is aborted by disconnecting (bsc#1133624).
References: https://www.suse.com/support/update/announcement/2019/suse-su-20192514-1/, https://bugzilla.suse.com/1133624, https://bugzilla.suse.com/1133625, https://bugzilla.suse.com/1145559, https://www.suse.com/security/cve/CVE-2019-11494, https://www.suse.com/security/cve/CVE-2019-11499, https://www.suse.com/security/cve/CVE-2019-11500
Affected packages
Package
Name: dovecot23
Purl: pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
