Mailinglist Archive: opensuse-updates (124 mails)

< Previous Next >
openSUSE-SU-2017:1807-1: moderate: Security update for dovecot22
openSUSE Security Update: Security update for dovecot22
______________________________________________________________________________

Announcement ID: openSUSE-SU-2017:1807-1
Rating: moderate
References: #1032248 #854512 #932386
Cross-References: CVE-2017-2669
Affected Products:
openSUSE Leap 42.2
______________________________________________________________________________

An update that solves one vulnerability and has two fixes
is now available.

Description:

This update for dovecot22 to version 2.2.30.2 fixes the following issues:

This security issue was fixed:

- CVE-2017-2669: Don't double-expand %variables in keys. If dict was used
as the authentication passdb, using specially crafted %variables in the
username could be used to cause DoS (bsc#1032248)

Additionally stronger SSL default ciphers are now used.

This non-security issue was fixed:

- Remove all references /etc/ssl/certs/. It should not be used anymore
(bsc#932386)

The version 2.2.30.2 also includes many fixes and enhancements:

- Multiple failed authentications within short time caused crashes.
- Use timing safe comparisons for everything related to passwords.
- Master process now sends SIGQUIT to all running children at shutdown,
which instructs them to close all the socket listeners immediately.
Restarting Dovecot should no longer fail due to some processes keeping
the listeners open for a long time.
- Add passdb { mechanisms=none } to match separate passdb lookup.
- Add passdb { username_filter } to use passdb only if user matches the
filter.
- Add dsync_commit_msgs_interval setting. It attempts to commit the
transaction after saving this many new messages.
- Support imapc_features=search without ESEARCH extension.
- Add imapc_features=fetch-bodystructure to pass through remote server's
FETCH BODY and BODYSTRUCTURE.
- Add quota=imapc backend to use GETQUOTA/GETQUOTAROOT on the remote
server.
- Add allow_invalid_cert and ssl_ca_file parameters.
- If dovecot.index.cache corruption is detected, reset only the one
corrupted mail instead
of the whole file.
- Add "firstsaved" field to doveadm mailbox status.
- Add old host's up/down and vhost count as parameters to
director_flush_socket.
- More fixes to automatically fix corruption in dovecot.list.index.
- Fix support for dsync_features=empty-header-workaround.
- IMAP NOTIFY wasn't working for non-INBOX if IMAP client hadn't enabled
modseq tracking via CONDSTORE/QRESYNC.
- Fix fts-lucene it to work again with mbox format.
- Some internal error messages may have contained garbage in v2.2.29.
- Re-encrypt when copying/moving mails and per-mailbox keys are used,
otherwise the copied mails can't be opened.

This update was imported from the SUSE:SLE-12:Update update project.


Patch Instructions:

To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2017-787=1

To bring your system up-to-date, use "zypper patch".


Package List:

- openSUSE Leap 42.2 (i586 x86_64):

dovecot22-2.2.30.2-5.4.1
dovecot22-backend-mysql-2.2.30.2-5.4.1
dovecot22-backend-mysql-debuginfo-2.2.30.2-5.4.1
dovecot22-backend-pgsql-2.2.30.2-5.4.1
dovecot22-backend-pgsql-debuginfo-2.2.30.2-5.4.1
dovecot22-backend-sqlite-2.2.30.2-5.4.1
dovecot22-backend-sqlite-debuginfo-2.2.30.2-5.4.1
dovecot22-debuginfo-2.2.30.2-5.4.1
dovecot22-debugsource-2.2.30.2-5.4.1
dovecot22-devel-2.2.30.2-5.4.1
dovecot22-fts-2.2.30.2-5.4.1
dovecot22-fts-debuginfo-2.2.30.2-5.4.1
dovecot22-fts-lucene-2.2.30.2-5.4.1
dovecot22-fts-lucene-debuginfo-2.2.30.2-5.4.1
dovecot22-fts-solr-2.2.30.2-5.4.1
dovecot22-fts-solr-debuginfo-2.2.30.2-5.4.1
dovecot22-fts-squat-2.2.30.2-5.4.1
dovecot22-fts-squat-debuginfo-2.2.30.2-5.4.1


References:

https://www.suse.com/security/cve/CVE-2017-2669.html
https://bugzilla.suse.com/1032248
https://bugzilla.suse.com/854512
https://bugzilla.suse.com/932386


< Previous Next >
This Thread
  • No further messages