dovecot 1:2.3.11.3+dfsg1-2ubuntu0.1 source package in Ubuntu

Changelog

dovecot (1:2.3.11.3+dfsg1-2ubuntu0.1) groovy-security; urgency=medium

  * SECURITY UPDATE: information disclosure via imap hibernation
    - debian/patches/CVE-2020-24386-1.patch: escape tag when sending it to
      imap-hibernate process in src/imap/imap-client-hibernate.c.
    - debian/patches/CVE-2020-24386-2.patch: add unit test for
      imap-client-hibernate in src/imap/Makefile.am,
      src/imap/imap-client-hibernate.c, src/imap/imap-client.h,
      src/imap/test-imap-client-hibernate.c.
    - CVE-2020-24386
  * SECURITY UPDATE: remote DoS via large number of MIME parts
    - debian/patches/CVE-2020-25275-1.patch: fix assert-crash when
      enforcing MIME part limit in src/lib-mail/message-parser.c,
      src/lib-mail/test-message-parser.c.
    - debian/patches/CVE-2020-25275-2.patch: don't generate invalid
      BODYSTRUCTURE when reaching MIME part limit in
      src/lib-imap/imap-bodystructure.c.
    - CVE-2020-25275

 -- Marc Deslauriers <email address hidden>  Mon, 28 Dec 2020 10:59:24 -0500

Upload details

Uploaded by:
Marc Deslauriers on 2020-12-28
Uploaded to:
Groovy
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
mail
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Groovy updates on 2021-01-04 main mail
Groovy security on 2021-01-04 main mail

Downloads

File Size SHA-256 Checksum
dovecot_2.3.11.3+dfsg1.orig-pigeonhole.tar.gz 1.5 MiB 73ffc0cff40b768f8dcf772957b58f3fe8b4a740ffe6fb6e9e66093aec41bc1c
dovecot_2.3.11.3+dfsg1.orig.tar.gz 7.0 MiB d3d9ea9010277f57eb5b9f4166a5d2ba539b172bd6d5a2b2529a6db524baafdc
dovecot_2.3.11.3+dfsg1.orig.tar.gz.asc 866 bytes fd73852972032af5e9b25992d94736d18460938ed21b9b6b10c9f77b5468ff89
dovecot_2.3.11.3+dfsg1-2ubuntu0.1.debian.tar.xz 64.4 KiB 2d41980f7a0fb3a580503a85f2125fd0a264783e88e6615520b1be85b55a85c0
dovecot_2.3.11.3+dfsg1-2ubuntu0.1.dsc 4.0 KiB db9e8c07e676074ebea6c57227f8f189108ca3f2a5c6095d668983725b42b90d

View changes file

Binary packages built by this source

dovecot-auth-lua: secure POP3/IMAP server - Lua authentication plugin

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains an authentication plugin allowing password and user
 databases to be implemented in Lua.

dovecot-auth-lua-dbgsym: debug symbols for dovecot-auth-lua
dovecot-core: secure POP3/IMAP server - core files

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot main server and its command line utility.

dovecot-core-dbgsym: debug symbols for dovecot-core
dovecot-dev: secure POP3/IMAP server - header files

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains header files needed to compile plugins for the Dovecot
 mail server.

dovecot-gssapi: secure POP3/IMAP server - GSSAPI support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides GSSAPI authentication support for Dovecot.

dovecot-gssapi-dbgsym: debug symbols for dovecot-gssapi
dovecot-imapd: secure POP3/IMAP server - IMAP daemon

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot IMAP server.

dovecot-imapd-dbgsym: debug symbols for dovecot-imapd
dovecot-ldap: secure POP3/IMAP server - LDAP support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides LDAP support for Dovecot.

dovecot-ldap-dbgsym: debug symbols for dovecot-ldap
dovecot-lmtpd: secure POP3/IMAP server - LMTP server

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot LMTP server.

dovecot-lmtpd-dbgsym: debug symbols for dovecot-lmtpd
dovecot-lucene: secure POP3/IMAP server - Lucene support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides Lucene full text search support for Dovecot.

dovecot-lucene-dbgsym: debug symbols for dovecot-lucene
dovecot-managesieved: secure POP3/IMAP server - ManageSieve server

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot ManageSieve server.

dovecot-managesieved-dbgsym: debug symbols for dovecot-managesieved
dovecot-mysql: secure POP3/IMAP server - MySQL support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides MySQL support for Dovecot.

dovecot-mysql-dbgsym: debug symbols for dovecot-mysql
dovecot-pgsql: secure POP3/IMAP server - PostgreSQL support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides PostgreSQL support for Dovecot.

dovecot-pgsql-dbgsym: debug symbols for dovecot-pgsql
dovecot-pop3d: secure POP3/IMAP server - POP3 daemon

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot POP3 server.

dovecot-pop3d-dbgsym: debug symbols for dovecot-pop3d
dovecot-sieve: secure POP3/IMAP server - Sieve filters support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides Sieve filters support for Dovecot.

dovecot-sieve-dbgsym: debug symbols for dovecot-sieve
dovecot-solr: secure POP3/IMAP server - Solr support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides Solr full text search support for Dovecot.

dovecot-solr-dbgsym: debug symbols for dovecot-solr
dovecot-sqlite: secure POP3/IMAP server - SQLite support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides SQLite support for Dovecot.

dovecot-sqlite-dbgsym: debug symbols for dovecot-sqlite
dovecot-submissiond: secure POP3/IMAP server - mail submission agent

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot Mail Submission Agent which implements a
 basic SMTP submission service with BURL support.

dovecot-submissiond-dbgsym: debug symbols for dovecot-submissiond