Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE Linux Enterprise 15: SUSE-SU-2019:0414-1 Moderate: Dovecot SSL Issue

suse
Calendar Grey February 15, 2019
Dist Suse Esm H88
SUSE Security Update: Security update for dovecot23 ________________________________________________
An update that solves one vulnerability and has two fixes is now available

Summary

This update for dovecot23 fixes the following issues: dovecot was updated to 2.3.3 release, bringing lots of bugfixes (bsc#1124356). Also the following security issue was fixed: - CVE-2019-3814: A vulnerability in Dovecot related to SSL client certificate authentication was fixed (bsc#1123022) The package changes: Updated pigeonhole to 0.5.3: - Fix assertion panic occurring when managesieve service fails to open INBOX while saving a Sieve script. This was caused by a lack of cleanup after failure. - Fix specific messages causing an assert panic with actions that compose a reply (e.g. vacation). With some rather weird input from the original message, the header folding algorithm (as used for composing the References header for the reply) got confused, causing the panic.

References

#1119850 #1123022 #1124356

Cross- CVE-2019-3814

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15

https://www.suse.com/security/cve/CVE-2019-3814.html

https://bugzilla.suse.com/1119850

https://bugzilla.suse.com/1123022

https://bugzilla.suse.com/1124356

Announcement ID: SUSE-SU-2019:0414-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here