sthen c429595b71 update to Dovecot 2.3.4.1, fixing some issues with client certificates.
ok brad (maintainer)

* CVE-2019-3814: If imap/pop3/managesieve/submission client has trusted
certificate with missing username field (ssl_cert_username_field), under
some configurations Dovecot mistakenly trusts the username provided via
authentication instead of failing.

* ssl_cert_username_field setting was ignored with external SMTP
AUTH, because none of the MTAs (Postfix, Exim) currently send the
cert_username field. This may have allowed users with trusted
certificate to specify any username in the authentication. This bug
didn't affect Dovecot's Submission service.
2019-02-08 13:34:40 +00:00
..
2018-09-04 12:46:09 +00:00
2019-01-11 01:51:34 +00:00
2018-10-16 20:28:09 +00:00
2017-02-27 18:25:50 +00:00
2019-01-01 18:01:20 +00:00
2018-02-25 22:20:56 +00:00
2017-05-07 18:01:21 +00:00
2019-02-04 17:00:42 +00:00
2016-03-08 17:30:43 +00:00
2018-09-04 12:46:09 +00:00
2018-11-01 04:22:15 +00:00
2018-04-14 10:14:04 +00:00
2018-11-27 09:00:30 +00:00
2018-09-18 08:18:01 +00:00
2018-06-22 00:03:31 +00:00
2017-05-10 12:47:56 +00:00
2019-01-26 10:25:09 +00:00
2017-11-19 00:53:16 +00:00
2016-06-08 20:12:30 +00:00
2018-09-04 12:46:09 +00:00
2018-07-12 10:16:06 +00:00
2019-01-06 17:18:08 +00:00
2018-09-04 12:46:09 +00:00
2018-08-31 10:31:41 +00:00
2015-06-19 12:44:49 +00:00
2018-10-28 12:14:02 +00:00
2017-05-25 17:47:08 +00:00
2018-09-04 12:46:09 +00:00
2019-02-01 23:55:59 +00:00
2017-07-05 10:22:05 +00:00
2019-01-01 20:43:21 +00:00
2018-11-29 17:03:34 +00:00
2018-11-24 11:27:49 +00:00
2016-10-11 15:59:52 +00:00
2018-03-21 07:36:15 +00:00
2019-01-25 10:22:26 +00:00
2017-04-11 12:53:49 +00:00
2015-11-16 11:29:05 +00:00
2015-09-19 09:05:52 +00:00
2019-01-24 16:53:37 +00:00
2019-01-24 17:10:55 +00:00
2016-02-29 23:42:21 +00:00
2018-12-04 15:16:48 +00:00
2016-11-02 17:04:24 +00:00
2019-02-02 01:59:32 +00:00
2018-09-04 12:46:09 +00:00
2016-08-03 13:06:41 +00:00
2016-01-12 13:19:37 +00:00
2018-11-16 20:46:23 +00:00
2018-09-04 12:46:09 +00:00
2016-08-03 13:06:41 +00:00
2016-04-12 15:19:39 +00:00
2018-06-29 22:16:08 +00:00
2018-05-20 08:19:25 +00:00
2018-05-20 08:19:25 +00:00
2018-05-20 08:19:25 +00:00
2017-10-23 17:10:49 +00:00
2019-01-25 07:41:05 +00:00