Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
89

Fedora 8: 2008-10797 Moderate: Dovecot Password Exposure Risk Mitigation

new possibility to store ssl passwords in different file linked to dovecot.conf via !include_try directive change permissions of deliver and dovecot.conf to prevent possible password exposure change permissions of deliver and dovecot.conf to prevent possible password exposure. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-10797 2008-12-07 02:15:14 --------------------------------------------------------------------------------Name : dovecot Product : Fedora 8 Version : 1.0.15 Release : 16.fc8 URL : https://dovecot.org/ Summary : Dovecot Secure imap server Description : Dovecot is an IMAP server for Linux/UNIX-like systems, written with security primarily in mind. It also contains a small POP3 server. It supports mail in either of maildir or mbox formats. The SQL drivers and authentication plugins are in their subpackages. --------------------------------------------------------------------------------Update Information: new possibility to store ssl passwords in different file linked to dovecot.conf via !include_try directive change permissions of deliver and dovecot.conf to prevent possible password exposure change permissions of deliver and dovecot.conf to prevent possible password exposure --------------------------------------------------------------------------------ChangeLog: * Tue Dec 2 2008 Michal Hlavinka - 1.0.15-16 - permissions of deliver and dovecot.conf from 1.0.15-15 reverted - password can be stored in different file readable only for root now * Mon Nov 3 2008 Michal Hlavinka - 1:1.0.15-15 - change permissions of deliver and dovecot.conf to prevent possible password exposure * Wed Oct 29 2008 Michal Hlavinka - 1:1.0.15-14 - fix handling of negative rights in the ACL plugin (Resolves: CVE-2008-4577) * Thu Aug 14 2008 Dan Horak - 1:1.0.15-13 - add missing defattr into subpackages - remove unused patches from CVS * Tue Jul 29 2008 Dan Horak -1:1.0.15-12 - really ask for the password during start-up * Tue Jul 29 2008 Dan Horák - 1:1.0.15-11 - final solution for #445200 (put the password into /etc/sysconfig/dovecot) * Tue Jul 1 2008 Dan Horák - 1:1.0.15-10 - bump release * Sun Jun 22 2008 Dan Horák - 1:1.0.15-1 - update to latest upstream 1.0.15 - Resolves: #452088 * Wed Jun 18 2008 Dan Horak - 1:1.0.14-9 - update init script (Resolves: #451838) * Sat Jun 7 2008 Dan Horak - 1:1.0.14-8 - build devel subpackage (Resolves: #306881) * Fri Jun 6 2008 Dan Horák - 1:1.0.14-7 - update to latest upstream stable (dovecot 1.0.14, sieve plugin 1.0.3) - Resolves: #445200, #448095, #450010 * Sun Mar 9 2008 Tomas Janousek - 1:1.0.13-6 - update to latest upstream stable (1.0.13) * Wed Feb 20 2008 Fedora Release Engineering - 1:1.0.10-5 - Autorebuild for GCC 4.3 * Mon Jan 7 2008 Tomas Janousek - 1:1.0.10-4 - update to latest upstream stable (1.0.10) * Wed Dec 5 2007 Jesse Keating - 1:1.0.7-3 - Bump for deps * Mon Nov 5 2007 Tomas Janousek - 1:1.0.7-2 - update to latest upstream stable (1.0.7) - added the winbind patch (#286351) --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update dovecot' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Nginx security patch for Fedora 8 resolves vulnerabilities in session management and improves access controls for heightened protection..Dovecot Update, Password Management, Fedora Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 07, 2009 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here