An update that solves seven vulnerabilities can now be installed.. # Security update for dovecot22 Announcement ID: SUSE-SU-2026:1641-1 Release Date: 2026-04-28T11:53:50Z Rating: important References: * bsc#1260895 * bsc#1260897 * bsc#1260898 * bsc#1260899 * bsc#1260900 * bsc#1260901 * bsc#1260902 Cross-References: * CVE-2025-59031 * CVE-2025-59032 * CVE-2026-27855 * CVE-2026-27856 * CVE-2026-27857 * CVE-2026-27858 * CVE-2026-27859 CVSS scores: * CVE-2025-59031 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-59031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-59031 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-59032 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59032 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59032 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27855 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-27855 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-27855 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-27856 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-27856 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27856 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27857 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27857 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27857 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27858 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27858 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27858 ( NVD ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27859 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27859 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27859 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for dovecot22 fixes the following issues: * CVE-2025-59031: decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing (bsc#1260895). * CVE-2025-59032: pigeonhole: ManageSieve panic occurs with sieve-connect as a client (bsc#1260902). * CVE-2026-27855: OTP driver vulnerable to replay attack (bsc#1260900). * CVE-2026-27856: Doveadm credentials were not checked using timing-safe checking function (bsc#1260899). * CVE-2026-27857: sending excessive parenthesis causes imap-login to use excessive memory (bsc#1260898). * CVE-2026-27858: pigeonhole: managesieve-login can allocate large amount of memory during authentication (bsc#1260901). * CVE-2026-27859: excessive RFC 2231 MIME parameters in email would can excessive CPU usage (bsc#1260897). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1641=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1641=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5LTSS (aarch64 ppc64le s390x x86_64) * dovecot22-backend-pgsql-debuginfo-2.2.31-19.32.1 * dovecot22-debugsource-2.2.31-19.32.1 * dovecot22-backend-sqlite-debuginfo-2.2.31-19.32.1 * dovecot22-backend-mysql-debuginfo-2.2.31-19.32.1 * dovecot22-backend-pgsql-2.2.31-19.32.1 * dovecot22-debuginfo-2.2.31-19.32.1 * dovecot22-2.2.31-19.32.1 * dovecot22-devel-2.2.31-19.32.1 * dovecot22-backend-sqlite-2.2.31-19.32.1 * dovecot22-backend-mysql-2.2.31-19.32.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * dovecot22-backend-pgsql-debuginfo-2.2.31-19.32.1 * dovecot22-debugsource-2.2.31-19.32.1 * dovecot22-backend-sqlite-debuginfo-2.2.31-19.32.1 * dovecot22-backend-mysql-debuginfo-2.2.31-19.32.1 * dovecot22-backend-pgsql-2.2.31-19.32.1 * dovecot22-debuginfo-2.2.31-19.32.1 * dovecot22-2.2.31-19.32.1 * dovecot22-devel-2.2.31-19.32.1 * dovecot22-backend-sqlite-2.2.31-19.32.1 * dovecot22-backend-mysql-2.2.31-19.32.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59031.html * https://www.suse.com/security/cve/CVE-2025-59032.html * https://www.suse.com/security/cve/CVE-2026-27855.html * https://www.suse.com/security/cve/CVE-2026-27856.html * https://www.suse.com/security/cve/CVE-2026-27857.html * https://www.suse.com/security/cve/CVE-2026-27858.html * https://www.suse.com/security/cve/CVE-2026-27859.html * https://bugzilla.suse.com/show_bug.cgi?id=1260895 * https://bugzilla.suse.com/show_bug.cgi?id=1260897 * https://bugzilla.suse.com/show_bug.cgi?id=1260898 * https://bugzilla.suse.com/show_bug.cgi?id=1260899 * https://bugzilla.suse.com/show_bug.cgi?id=1260900 * https://bugzilla.suse.com/show_bug.cgi?id=1260901 * https://bugzilla.suse.com/show_bug.cgi?id=1260902 . SUSE's important update for dovecot22 fixes multiple issues including memory and security vulnerabilities. Install now.. Linux security fixes. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for dovecot22 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0018-1 Rating: important References: #1180405 Cross-References: CVE-2020-24386 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Enterprise Storage 5 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for dovecot22 fixes the following issues: - CVE-2020-24386: Fixed an issue with IMAP hibernation that allowed users to access other users' emails (bsc#1180405). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-18=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patchSUSE-OpenStack-Cloud-Crowbar-8-2021-18=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2021-18=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-18=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2021-18=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-18=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-18=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-18=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2021-18=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-18=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-18=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-18=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2021-18=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2021-18=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-18=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2021-18=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-18=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE OpenStack Cloud 9 (x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE OpenStack Cloud 8 (x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE OpenStack Cloud 7 (s390x x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 dovecot22-devel-2.2.31-19.25.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE LinuxEnterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - SUSE Enterprise Storage 5 (aarch64 x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 - HPE Helion Openstack 8 (x86_64): dovecot22-2.2.31-19.25.1 dovecot22-backend-mysql-2.2.31-19.25.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.25.1 dovecot22-backend-pgsql-2.2.31-19.25.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.25.1 dovecot22-backend-sqlite-2.2.31-19.25.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.25.1 dovecot22-debuginfo-2.2.31-19.25.1 dovecot22-debugsource-2.2.31-19.25.1 References: https://www.suse.com/security/cve/CVE-2020-24386.html https://bugzilla.suse.com/1180405 . SUSE Security Patch addresses critical IMAP connectivity problem in dovecot22. Ensure to implement the required updates across various distributions.. SUSE Dovecot Update, IMAP Access Issue, Security Update, Email Software Patch, SUSE Security Advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for dovecot22 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2454-1 Rating: important References: #1145559 Cross-References: CVE-2019-11500 Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Enterprise Storage 5 SUSE Enterprise Storage 4 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for dovecot22 fixes the following issues: - CVE-2019-11500: Fixed a potential remote code execution in the IMAP and ManageSieve protocol parsers (bsc#1145559). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-2454=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2019-2454=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-2454=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2019-2454=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-2454=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2019-2454=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-2454=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2019-2454=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2019-2454=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-2454=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-2454=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2019-2454=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-2454=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2019-2454=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-2454=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2019-2454=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-2454=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2019-2454=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE OpenStack Cloud 8 (x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE OpenStack Cloud 7 (s390x x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 dovecot22-devel-2.2.31-19.17.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 dovecot22-devel-2.2.31-19.17.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64ppc64le s390x x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Enterprise Storage 5 (aarch64 x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - SUSE Enterprise Storage 4 (x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 - HPE Helion Openstack 8 (x86_64): dovecot22-2.2.31-19.17.1 dovecot22-backend-mysql-2.2.31-19.17.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.17.1 dovecot22-backend-pgsql-2.2.31-19.17.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.17.1 dovecot22-backend-sqlite-2.2.31-19.17.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.17.1 dovecot22-debuginfo-2.2.31-19.17.1 dovecot22-debugsource-2.2.31-19.17.1 References: https://www.suse.com/security/cve/CVE-2019-11500.html https://bugzilla.suse.com/1145559 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for dovecot22 ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2632-1 Rating: important References: #1082828 Cross-References: CVE-2017-15130 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for dovecot22 fixes the following issues: Security issue fixed: - CVE-2017-15130: Fixed a potential denial of service via TLS SNI config lookups, which would slow the process down and could have led to exhaustive memory allocation and/or process restarts (bsc#1082828) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2018-1844=1 - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2018-1844=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2018-1844=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2018-1844=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -tpatch SUSE-SLE-SERVER-12-SP3-2018-1844=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2018-1844=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2018-1844=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2018-1844=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2018-1844=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): dovecot22-2.2.31-19.11.1 dovecot22-backend-mysql-2.2.31-19.11.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.11.1 dovecot22-backend-pgsql-2.2.31-19.11.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.11.1 dovecot22-backend-sqlite-2.2.31-19.11.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.11.1 dovecot22-debuginfo-2.2.31-19.11.1 dovecot22-debugsource-2.2.31-19.11.1 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): dovecot22-debuginfo-2.2.31-19.11.1 dovecot22-debugsource-2.2.31-19.11.1 dovecot22-devel-2.2.31-19.11.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): dovecot22-2.2.31-19.11.1 dovecot22-backend-mysql-2.2.31-19.11.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.11.1 dovecot22-backend-pgsql-2.2.31-19.11.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.11.1 dovecot22-backend-sqlite-2.2.31-19.11.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.11.1 dovecot22-debuginfo-2.2.31-19.11.1 dovecot22-debugsource-2.2.31-19.11.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (ppc64le x86_64): dovecot22-2.2.31-19.11.1 dovecot22-backend-mysql-2.2.31-19.11.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.11.1 dovecot22-backend-pgsql-2.2.31-19.11.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.11.1 dovecot22-backend-sqlite-2.2.31-19.11.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.11.1 dovecot22-debuginfo-2.2.31-19.11.1 dovecot22-debugsource-2.2.31-19.11.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): dovecot22-2.2.31-19.11.1 dovecot22-backend-mysql-2.2.31-19.11.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.11.1 dovecot22-backend-pgsql-2.2.31-19.11.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.11.1 dovecot22-backend-sqlite-2.2.31-19.11.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.11.1 dovecot22-debuginfo-2.2.31-19.11.1 dovecot22-debugsource-2.2.31-19.11.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): dovecot22-2.2.31-19.11.1 dovecot22-backend-mysql-2.2.31-19.11.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.11.1 dovecot22-backend-pgsql-2.2.31-19.11.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.11.1 dovecot22-backend-sqlite-2.2.31-19.11.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.11.1 dovecot22-debuginfo-2.2.31-19.11.1 dovecot22-debugsource-2.2.31-19.11.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): dovecot22-2.2.31-19.11.1 dovecot22-backend-mysql-2.2.31-19.11.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.11.1 dovecot22-backend-pgsql-2.2.31-19.11.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.11.1 dovecot22-backend-sqlite-2.2.31-19.11.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.11.1 dovecot22-debuginfo-2.2.31-19.11.1 dovecot22-debugsource-2.2.31-19.11.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): dovecot22-2.2.31-19.11.1 dovecot22-backend-mysql-2.2.31-19.11.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.11.1 dovecot22-backend-pgsql-2.2.31-19.11.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.11.1 dovecot22-backend-sqlite-2.2.31-19.11.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.11.1 dovecot22-debuginfo-2.2.31-19.11.1 dovecot22-debugsource-2.2.31-19.11.1 - SUSEEnterprise Storage 4 (x86_64): dovecot22-2.2.31-19.11.1 dovecot22-backend-mysql-2.2.31-19.11.1 dovecot22-backend-mysql-debuginfo-2.2.31-19.11.1 dovecot22-backend-pgsql-2.2.31-19.11.1 dovecot22-backend-pgsql-debuginfo-2.2.31-19.11.1 dovecot22-backend-sqlite-2.2.31-19.11.1 dovecot22-backend-sqlite-debuginfo-2.2.31-19.11.1 dovecot22-debuginfo-2.2.31-19.11.1 dovecot22-debugsource-2.2.31-19.11.1 References: https://www.suse.com/security/cve/CVE-2017-15130.html https://bugzilla.suse.com/1082828 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.