openSUSE-SU-2019:2278-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:2278-1
openSUSE-SU-2019:2278-1
Summary: Security update for dovecot23
Details: This update for dovecot23 fixes the following issue: - CVE-2019-11500: Fixed the NUL byte handling in IMAP and ManageSieve protocol parsers. (bsc#1145559) - CVE-2019-11499: Fixed a vulnerability where the submission-login would crash over a TLS secured channel (bsc#1133625). - CVE-2019-11494: Fixed a denial of service if the authentication is aborted by disconnecting (bsc#1133624). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/4ZX4AZ5LGOZTCD7HGA6Y7KWE3LMXAGVL/#4ZX4AZ5LGOZTCD7HGA6Y7KWE3LMXAGVL, https://bugzilla.suse.com/1133624, https://bugzilla.suse.com/1133625, https://bugzilla.suse.com/1145559, https://www.suse.com/security/cve/CVE-2019-11494, https://www.suse.com/security/cve/CVE-2019-11499, https://www.suse.com/security/cve/CVE-2019-11500
Affected packages
Package
Name: dovecot23
Purl: pkg:rpm/opensuse/dovecot23&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
