Secure imap and pop3 server
91c7c1a6c5
CVE-2021-29157: Dovecot does not correctly escape kid and azp fields in JWT tokens. This may be used to supply attacker controlled keys to validate tokens, if attacker has local access (#1979833) CVE-2021-33515: On-path attacker could have injected plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the client Add TSLv1.3 support to min_protocols. Resolves: #1979833 |
||
---|---|---|
.gitignore | ||
dovecot-1.0.beta2-mkcert-permissions.patch | ||
dovecot-1.0.rc7-mkcert-paths.patch | ||
dovecot-2.0-defaultconfig.patch | ||
dovecot-2.1-privatetmp.patch | ||
dovecot-2.1.4-postreleasefix.patch | ||
dovecot-2.1.10-waitonline.patch | ||
dovecot-2.2-80ed82a93c1a.patch | ||
dovecot-2.2.20-initbysystemd.patch | ||
dovecot-2.2.22-systemd_w_protectsystem.patch | ||
dovecot-2.3.0.1-libxcrypt.patch | ||
dovecot-2.3.6-opensslhmac.patch | ||
dovecot-2.3.8-blockcount.patch | ||
dovecot-2.3.11-bigkey.patch | ||
dovecot-2.3.14-opensslv3.patch | ||
dovecot.conf.5 | ||
dovecot.init | ||
dovecot.pam | ||
dovecot.spec | ||
dovecot.sysconfig | ||
dovecot.tmpfilesd | ||
gating.yaml | ||
prestartscript | ||
sources |