Mageia 2019-0261: dovecot security update
Summary
Updated dovecot packages fix security vulnerability:
IMAP protocol parser does not properly handle NUL byte when scanning data
in quoted strings, leading to out of bounds heap memory writes.
References
- https://bugs.mageia.org/show_bug.cgi?id=25371
- https://dovecot.org/pipermail/dovecot/2019-August/116875.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11500
Resolution
MGASA-2019-0261 - Updated dovecot packages fix security vulnerability
SRPMS
- 6/core/dovecot-2.2.36.4-1.mga6
- 7/core/dovecot-2.3.7.2-1.mga7