HomeFreeBSD

MFH: r489098 r489515 r492245

Description

MFH: r489098 r489515 r492245

mail/dovecot: Pick up a mailinglist patch for solr/tika separation.

solr and tika currently use the same http client connection. Upstream
made the attached patches in response to my (ler@) bug report.

Obtained from: upstream mailing list.

mail/dovecot: Pick up mailing list patch for imap-preauth vs. stats-writer.

see the dovecot mailing list thread on imap-preauth and stats-writer between
Stephan Bosch and a FreeBSD user

Obtained from: upstream mailing list.

mail/dovecot: upgrade to 2.3.4.1

  • CVE-2019-3814: If imap/pop3/managesieve/submission client has trusted certificate with missing username field (ssl_cert_username_field), under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing.
  • ssl_cert_username_field setting was ignored with external SMTP AUTH, because none of the MTAs (Postfix, Exim) currently send the cert_username field. This may have allowed users with trusted certificate to specify any username in the authentication. This bug didn't affect Dovecot's Submission service.

PR: 235523
Submitted by: pascal.christen@hostpoint.ch
Security: 1340fcc1-2953-11e9-bc44-a4badb296695
Security: CVE-2019-3814

Approved by: ports-secteam (joneum)

Details

Provenance
lerAuthored on
Parents
rP492247: Update to 0.54.0
Branches
Unknown
Tags
Unknown