package/dovecot: security bump to version 2.3.6
authorBernd Kuhls <bernd.kuhls@t-online.de>
Tue, 30 Apr 2019 18:08:21 +0000 (20:08 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 30 Apr 2019 20:43:22 +0000 (22:43 +0200)
commit70784619bc20ec2152fd58eecae24f99710ab1e8
tree2136c0d9e990ba659e4352942a15b8d89669f99c
parent3d8e1ad1f36392a68ea7291c8da1e978b7e99dd8
package/dovecot: security bump to version 2.3.6

Fixes
* CVE-2019-11494: Submission-login crashed with signal 11 due to null
  pointer access when authentication was aborted by disconnecting.
* CVE-2019-11499: Submission-login crashed when authentication was
  started over TLS secured channel and invalid authentication message
  was sent.

Release notes:
https://dovecot.org/pipermail/dovecot-news/2019-April/000408.html

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/dovecot/dovecot.hash
package/dovecot/dovecot.mk