e1f99b1299dovecot updated to 2.3.16, pigeonhole to 0.5.16 fixes several regressions (#1997583) Resolves: #1997583
Michal Hlavinka
2021-08-25 22:23:07 +0200
d3bbb3608falso spec file change
Michal Hlavinka
2021-08-20 22:51:18 +0200
98b241328afix ftbfs for s390x
Michal Hlavinka
2021-08-20 22:12:05 +0200
76cf16c36ffix release number
Michal Hlavinka
2021-08-20 21:41:35 +0200
5a2167681cdovecot updated to 2.3.16, pigeonhole to 0.5.16 fixes several regressions
Michal Hlavinka
2021-08-20 21:40:35 +0200
009d8cd9d0Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
Mohan Boddu
2021-08-09 19:51:47 +0000
91c7c1a6c5dovecot updated to 2.3.15, pigeonhole updated to 0.5.15 CVE-2021-29157: Dovecot does not correctly escape kid and azp fields in JWT tokens. This may be used to supply attacker controlled keys to validate tokens, if attacker has local access (#1979833) CVE-2021-33515: On-path attacker could have injected plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the client Add TSLv1.3 support to min_protocols. Resolves: #1979833
Michal Hlavinka
2021-07-21 11:29:52 +0200
1e547c27d1fix mail storage block count parsing (#1974281) Resolves: #1974281
Michal Hlavinka
2021-07-14 11:41:00 +0200
7eba6ac53fAdding gating.yaml
Jakub Haruda
2021-06-30 18:47:32 +0200
b920232ea6fix spec file condition
Michal Hlavinka
2021-06-23 11:32:21 +0200
2e3cc75314fix FTBFS
Michal Hlavinka
2021-06-23 09:58:10 +0200
f838a05fb9dovecot updated to 2.3.15, pigeonhole updated to 0.5.15 CVE-2021-29157: Dovecot does not correctly escape kid and azp fields in JWT tokens. This may be used to supply attacker controlled keys to validate tokens, if attacker has local access. CVE-2021-33515: On-path attacker could have injected plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the client. Add TSLv1.3 support to min_protocols. Allow configuring ssl_cipher_suites. (for TLSv1.3+)
Michal Hlavinka
2021-06-21 23:25:54 +0200
9fbd075d80Rebuilt for RHEL 9 BETA for openssl 3.0
Mohan Boddu
2021-06-16 03:24:15 +0000
0dbbfacb4acompatibility with openssl 3.0 - apply patch Resolves: #1962035
Michal Hlavinka
2021-06-04 10:33:13 +0200
45842c647fcompatibility with openssl 3.0 Resolves: #1962035
Michal Hlavinka
2021-06-04 10:21:12 +0200
9e2964f1ddRebuild for ICU 69
Pete Walter
2021-05-20 00:58:00 +0100
ec859bf9deRebuild for ICU 69
Pete Walter
2021-05-19 16:45:17 +0100
4345d3c47bRe-enable LTO
Jeff Law
2021-05-10 12:08:39 -0600
da1792e8ca- Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937
Mohan Boddu
2021-04-15 23:08:44 +0000
db7d02b1ebMerged update from upstream sources
DistroBaker
2021-04-04 23:30:41 +0000
25d565523cdovecot updated to 2.3.14, pigeonhole to 0.5.14 use OpenSSL's implementation of HMAC Remove autocreate, expire, snarf and mail-filter plugins. Remove cydir storage driver. Remove XZ/LZMA write support. Read support will be removed in future release.
Michal Hlavinka
2021-03-22 21:06:01 +0100
8550d54facdo not use own implementation of HMAC, use OpenSSL
Michal Hlavinka
2021-03-22 19:30:17 +0100
4ca2e7f87eMerged update from upstream sources
DistroBaker
2021-02-09 10:57:12 +0000
abd5abe3b4rebuild for libpq ABI fix
Pavel Raiskup
2021-02-08 09:24:17 +0100
b848a91daeMerged update from upstream sources
DistroBaker
2021-02-01 13:33:44 +0000
886a96b230use make macros
Michal Hlavinka
2021-02-01 13:51:01 +0100
ec7cbddd9eMerged update from upstream sources
DistroBaker
2021-01-18 14:18:00 +0000
821365c01cMerged update from upstream sources
DistroBaker
2021-01-18 13:48:03 +0000
2860368c09fix multilib issues
Michal Hlavinka
2021-01-18 14:33:47 +0100
abd275bba1bump release and rebuild
Michal Hlavinka
2021-01-18 13:57:17 +0100
854458490aMerged update from upstream sources
DistroBaker
2021-01-07 18:13:36 +0000
f1771ed0fafix rundir location
Michal Hlavinka
2021-01-07 18:28:31 +0100
6a5d12aed1Merged update from upstream sources
DistroBaker
2021-01-06 13:45:51 +0000
cc81c97592fix release number
Michal Hlavinka
2021-01-06 14:01:36 +0100
b0939d59a8Merged update from upstream sources
DistroBaker
2021-01-06 12:21:51 +0000
e1b1e2910cfix patch
Michal Hlavinka
2021-01-06 11:43:31 +0100
432e04624ddovecot updated to 2.3.13, pigeonhole to 0.5.13 CVE-2020-24386: Specially crafted command can cause IMAP hibernate to allow logged in user to access other people's emails and filesystem information. Metric filter and global event filter variable syntax changed to a SQL-like format. auth: Added new aliases for %{variables}. Usage of the old ones is possible, but discouraged. auth: Removed RPA auth mechanism, SKEY auth mechanism, NTLM auth mechanism and related password schemes. auth: Removed passdb-sia, passdb-vpopmail and userdb-vpopmail. auth: Removed postfix postmap socket
Michal Hlavinka
2021-01-06 11:29:46 +0100
f8f94ccbdfdovecot updated to 2.3.13, pigeonhole to 0.5.13 CVE-2020-24386: Specially crafted command can cause IMAP hibernate to allow logged in user to access other people's emails and filesystem information. Metric filter and global event filter variable syntax changed to a SQL-like format. auth: Added new aliases for %{variables}. Usage of the old ones is possible, but discouraged. auth: Removed RPA auth mechanism, SKEY auth mechanism, NTLM auth mechanism and related password schemes. auth: Removed passdb-sia, passdb-vpopmail and userdb-vpopmail. auth: Removed postfix postmap socket
Michal Hlavinka
2021-01-04 19:46:26 +0100
68b9de8c8eMerged update from upstream sources
DistroBaker
2021-01-04 11:44:19 +0000
5e0f363767change run directory from /var/run to /run (#1777922)
Michal Hlavinka
2021-01-04 10:18:56 +0100
b73f4c06b0Add BuildRequires: make
Tom Stellard
2020-12-17 04:42:04 +0000
4284ee2182drop libsodium requirement (#1890230)
Michal Hlavinka
2020-12-04 19:39:56 +0100
e8d850ed60Merged update from upstream sources
DistroBaker
2020-10-27 17:30:34 +0100
4ca072df4denable zstd support
Michal Hlavinka
2020-10-20 15:39:01 +0200
29ed947aaefix gssapi issue
Michal Hlavinka
2020-09-02 11:58:34 +0200
98f6723298fix FTBFS on 32bit systems
Michal Hlavinka
2020-08-26 19:06:39 +0200
b50f4be969Disable LTO for now
Jeff Law
2020-08-17 14:52:59 -0600
8f461376e7CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. CVE-2020-12673: Dovecot's NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-10967: lmtp/submission: Issuing the RCPT command with an address that has the empty quoted string as local-part causes the lmtp service to crash. CVE-2020-12674: Dovecot's RPA mechanism implementation accepts zero-length message, which leads to assert-crash later on.
Michal Hlavinka
2020-08-15 18:22:04 +0200
4e11662dbedovecot updated to 2.3.10.1 fixes CVE-2020-10967, CVE-2020-10958, CVE-2020-10957
Michal Hlavinka
2020-05-18 18:12:36 +0200
64b3f1c790dovecot updated to 2.3.10, pigeonhole updated to 0.5.10
Michal Hlavinka
2020-04-21 19:12:22 +0200
1040ee253bdovecot updated to 2.3.9.3 fixes CVE-2020-7046: Truncated UTF-8 can be used to DoS submission-login and lmtp processes. fixes CVE-2020-7957: Specially crafted mail can crash snippet generation.
Michal Hlavinka
2020-02-12 15:16:26 +0100
fc993dbf7dfix permissions of ghost files
Michal Hlavinka
2020-01-09 15:31:55 +0100
deb9d38bedCVE-2019-19722: Mails with group addresses in From or To fields caused crash in push notification drivers.
Michal Hlavinka
2019-12-19 15:17:08 +0100
29bbb4096adovecot updated to 2.3.9, pigeonhole updated to 0.5.9
Michal Hlavinka
2019-12-05 18:10:32 +0100
71a430ba9ddovecot updated to 2.3.8, pigeonhole 0.5.8
Michal Hlavinka
2019-10-10 13:59:30 +0200
2a068bb479add more buildrequires
Michal Hlavinka
2019-10-10 13:04:27 +0200
c4e66bf297dovecot updated to 2.3.7.2, pigeonhole 0.5.7.2 fixes CVE-2019-11500: IMAP protocol parser does not properly handle NUL byte when scanning data in quoted strings, leading to out of bounds heap memory writes
Michal Hlavinka
2019-08-29 09:44:35 +0200
581436bcf3dovecot updated to 2.3.7.1, pigeonhole updated to 0.5.7.1
Michal Hlavinka
2019-08-19 15:25:24 +0200
b242522b1euse /run instead of /var/run (#1706372)
Michal Hlavinka
2019-05-13 16:15:48 +0200
82caf4b446dovecot updated to 2.3.6, pigeonhole updated to 0.5.6
Michal Hlavinka
2019-05-02 13:49:42 +0200
e9463061ffdovecot updated to 2.3.5.2 fixes CVE-2019-10691: Trying to login with 8bit username containing invalid UTF8 input causes auth process to crash if auth policy is enabled.
Michal Hlavinka
2019-04-18 14:45:08 +0200
b9ba0bbcd9dovecot updated to 2.3.5.1 CVE-2019-7524: Missing input buffer size validation leads into arbitrary buffer overflow when reading fts or pop3 uidl header from Dovecot index.
Michal Hlavinka
2019-03-28 14:56:50 +0100
04058156dcdovecot updated to 2.3.5, pigeonhole updated to 0.5.5
Michal Hlavinka
2019-03-06 15:41:52 +0100
Rebuilt for libcrypt.so.2 (#1666033)
Björn Esser
2019-01-14 19:00:28 +0100
d111f39fa0fix tests
Michal Hlavinka
2019-01-09 17:46:45 +0100
aa4c0451e3dovecot updated to 2.3.4, pigeonhole updated to 0.5.4
Michal Hlavinka
2019-01-09 17:09:09 +0100
6d73939b5fdovecot updated to 2.3.3, pigeonhole pdated to 0.5.3 doveconf hides more secrets now in the default output NUL bytes in mail headers can cause truncated replies when fetched. virtual plugin: Some searches used 100% CPU for many seconds dsync assert-crashed with acl plugin in some situations. imapc: Fixed various assert-crashes when reconnecting to server.
Michal Hlavinka
2018-10-02 10:41:13 +0200
ac25631e92fix dovecot-init service syntax error (#1635017)
Michal Hlavinka
2018-10-02 10:36:12 +0200
571d3e074eBuildRequires: s/postgresql-devel/libpq-devel/
Pavel Raiskup
2018-09-05 15:07:12 +0200
0813442466do not try to generate ssl-params as its obsolete (#1614640)
Michal Hlavinka
2018-08-13 17:51:07 +0200