dovecot 1:2.3.7.2-1ubuntu3.2 source package in Ubuntu

Changelog

dovecot (1:2.3.7.2-1ubuntu3.2) focal-security; urgency=medium

  * SECURITY UPDATE: DoS via deeply nested MIME parts
    - debian/patches/CVE-2020-12100/*.patch: backports of upstream patches
      to fix the issue.
    - CVE-2020-12100
  * SECURITY UPDATE: DoS via incorrect NTLM message buffer size
    - debian/patches/CVE-2020-12673/*.patch: check buffer length in
      src/lib-ntlm/ntlm-message.c.
    - CVE-2020-12673
  * SECURITY UPDATE: DoS via zero-length message
    - debian/patches/CVE-2020-12674/*.patch: fail on zero-length buffer in
      src/auth/mech-rpa.c.
    - CVE-2020-12674

 -- Marc Deslauriers <email address hidden>  Wed, 05 Aug 2020 10:26:17 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
mail
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
dovecot_2.3.7.2.orig.tar.gz 6.7 MiB 666ce084760a47e601d49a9be3c7993c48789d332631e8dfb45f443b367b1260
dovecot_2.3.7.2-1ubuntu3.2.debian.tar.xz 550.7 KiB 8736ae205d58a16d109ce1590705c32a94985c31397478529e8483461f74f530
dovecot_2.3.7.2-1ubuntu3.2.dsc 3.4 KiB b1113358adcc3cc756083c775cd4f04325219f1264d314523ce8ed1b00429b32

View changes file

Binary packages built by this source

dovecot-auth-lua: secure POP3/IMAP server - Lua authentication plugin

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains an authentication plugin allowing password and user
 databases to be implemented in Lua.

dovecot-auth-lua-dbgsym: debug symbols for dovecot-auth-lua
dovecot-core: secure POP3/IMAP server - core files

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot main server and its command line utility.

dovecot-core-dbgsym: debug symbols for dovecot-core
dovecot-dev: secure POP3/IMAP server - header files

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains header files needed to compile plugins for the Dovecot
 mail server.

dovecot-gssapi: secure POP3/IMAP server - GSSAPI support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides GSSAPI authentication support for Dovecot.

dovecot-gssapi-dbgsym: debug symbols for dovecot-gssapi
dovecot-imapd: secure POP3/IMAP server - IMAP daemon

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot IMAP server.

dovecot-imapd-dbgsym: debug symbols for dovecot-imapd
dovecot-ldap: secure POP3/IMAP server - LDAP support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides LDAP support for Dovecot.

dovecot-ldap-dbgsym: debug symbols for dovecot-ldap
dovecot-lmtpd: secure POP3/IMAP server - LMTP server

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot LMTP server.

dovecot-lmtpd-dbgsym: debug symbols for dovecot-lmtpd
dovecot-lucene: secure POP3/IMAP server - Lucene support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides Lucene full text search support for Dovecot.

dovecot-lucene-dbgsym: debug symbols for dovecot-lucene
dovecot-managesieved: secure POP3/IMAP server - ManageSieve server

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot ManageSieve server.

dovecot-managesieved-dbgsym: debug symbols for dovecot-managesieved
dovecot-mysql: secure POP3/IMAP server - MySQL support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides MySQL support for Dovecot.

dovecot-mysql-dbgsym: debug symbols for dovecot-mysql
dovecot-pgsql: secure POP3/IMAP server - PostgreSQL support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides PostgreSQL support for Dovecot.

dovecot-pgsql-dbgsym: debug symbols for dovecot-pgsql
dovecot-pop3d: secure POP3/IMAP server - POP3 daemon

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot POP3 server.

dovecot-pop3d-dbgsym: debug symbols for dovecot-pop3d
dovecot-sieve: secure POP3/IMAP server - Sieve filters support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides Sieve filters support for Dovecot.

dovecot-sieve-dbgsym: debug symbols for dovecot-sieve
dovecot-solr: secure POP3/IMAP server - Solr support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides Solr full text search support for Dovecot.

dovecot-solr-dbgsym: debug symbols for dovecot-solr
dovecot-sqlite: secure POP3/IMAP server - SQLite support

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package provides SQLite support for Dovecot.

dovecot-sqlite-dbgsym: debug symbols for dovecot-sqlite
dovecot-submissiond: secure POP3/IMAP server - mail submission agent

 Dovecot is a mail server whose major goals are security and extreme
 reliability. It tries very hard to handle all error conditions and verify
 that all data is valid, making it nearly impossible to crash. It supports
 mbox/Maildir and its own dbox/mdbox formats, and should also be pretty
 fast, extensible, and portable.
 .
 This package contains the Dovecot Mail Submission Agent which implements a
 basic SMTP submission service with BURL support.

dovecot-submissiond-dbgsym: debug symbols for dovecot-submissiond
mail-stack-delivery: transitional package

 This is a transitional package. It can safely be removed.
 .
 If you had formerly set up dovecot via mail-stack-delivery this package will
 still have the configuration /etc/dovecot/conf.d/99-mail-stack-delivery.conf
 associated to it which will be removed if you purge the package.