This update for dovecot23 fixes the following issues: dovecot was updated to 2.3.3 release, bringing lots of bugfixes (bsc#1124356). Also the following security issue was fixed: - CVE-2019-3814: A vulnerability in Dovecot related to SSL client certificate authentication was fixed (bsc#1123022) The package changes: Updated pigeonhole to 0.5.3: - Fix assertion panic occurring when managesieve service fails to open INBOX while saving a Sieve script. This was caused by a lack of cleanup after failure. - Fix specific messages causing an assert panic with actions that compose a reply (e.g. vacation). With some rather weird input from the original message, the header folding algorithm (as used for composing the References header for the reply) got confused, causing the panic.
#1119850 #1123022 #1124356
Cross- CVE-2019-3814
Affected Products:
SUSE Linux Enterprise Module for Server Applications 15
https://www.suse.com/security/cve/CVE-2019-3814.html
https://bugzilla.suse.com/1119850
https://bugzilla.suse.com/1123022
https://bugzilla.suse.com/1124356
Get the latest Linux and open source security news straight to your inbox.