Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 8: 2008-10797 Moderate: Dovecot Password Exposure Risk Mitigation

fedora
Calendar Grey January 7, 2009
Dist Fedora Esm H88
Nginx security patch for Fedora 8 resolves vulnerabilities in session management and improves access controls for heightened protection.
new possibility to store ssl passwords in different file linked to dovecot.conf via !include_try directive change permissions of deliver and dovecot.conf to prevent possible pass...

Summary

Dovecot is an IMAP server for Linux/UNIX-like systems, written with security

primarily in mind. It also contains a small POP3 server. It supports mail

in either of maildir or mbox formats.

The SQL drivers and authentication plugins are in their subpackages.

new possibility to store ssl passwords in different file linked to dovecot.conf

via !include_try directive change permissions of deliver and dovecot.conf to

prevent possible password exposure change permissions of deliver and

dovecot.conf to prevent possible password exposure

* Tue Dec 2 2008 Michal Hlavinka - 1.0.15-16

- permissions of deliver and dovecot.conf from 1.0.15-15 reverted

- password can be stored in different file readable only for root now

* Mon Nov 3 2008 Michal Hlavinka - 1:1.0.15-15

- change permissions of deliver and dovecot.conf to prevent possible password exposure

* Wed Oct 29 2008 Michal Hlavinka - 1:1.0.15-14

- fix handling of negative rights in the ACL plugin (Resolves: CVE-2008-4577)

* Thu Aug 14 2008 Dan Horak - 1:1.0.15-13

- add missing defattr into subpackages

- remove unused patches from CVS

* Tue Jul 29 2008 Dan Horak - 1:1.0.15-12

- really ask for the password during start-up

* Tue Jul 29 2008 Dan Horák - 1:1.0.15-11

- final solution for #445200 (put the password into /etc/sysconfig/dovecot)

* Tue Jul 1 2008 Dan Horák - 1:1.0.15-10

- bump release

* Sun Jun 22 2008 Dan Horák - 1:1.0.15-1

- update to latest upstream 1.0.15

- Resolves: #452088

* Wed Jun 18 2008 Dan Horak - 1:1.0.14-9

- update init script (Resolves: #451838)

* Sat Jun 7 2008 Dan Horak - 1:1.0.14-8

- build devel subpackage (Resolves: #306881)

* Fri Jun 6 2008 Dan Horák - 1:1.0.14-7

- update to latest upstream stable (dovecot 1.0.14, sieve plugin 1.0.3)

- Resolves: #445200, #448095, #450010

* Sun Mar 9 2008 Tomas Janousek - 1:1.0.13-6

- update to latest upstream stable (1.0.13)

* Wed Feb 20 2008 Fedora Release Engineering - 1:1.0.10-5

- Autorebuild for GCC 4.3

* Mon Jan 7 2008 Tomas Janousek - 1:1.0.10-4

- update to latest upstream stable (1.0.10)

* Wed Dec 5 2007 Jesse Keating - 1:1.0.7-3

- Bump for deps

* Mon Nov 5 2007 Tomas Janousek - 1:1.0.7-2

- update to latest upstream stable (1.0.7)

- added the winbind patch (#286351)

su -c 'yum update dovecot' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 8
Version: 1.0.15
Release: 16.fc8
Summary: Dovecot Secure imap server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here