sthen e02f604d53 update to Dovecot 2.3.15
CVE-2021-29157: Dovecot does not correctly escape kid and azp fields in
JWT tokens. This may be used to supply attacker controlled keys to
validate tokens, if attacker has local access.

CVE-2021-33515: On-path attacker could have injected plaintext commands
before STARTTLS negotiation that would be executed after STARTTLS
finished with the client.
2021-06-22 11:29:26 +00:00
..
2021-06-22 11:29:26 +00:00
2019-05-01 13:41:20 +00:00