package/dovecot: security bump to version 2.3.5.2
authorPeter Korsgaard <peter@korsgaard.com>
Thu, 25 Apr 2019 10:26:18 +0000 (12:26 +0200)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Fri, 26 Apr 2019 07:13:57 +0000 (09:13 +0200)
commit89c7e417ede23c9f3583391a882c10d825527727
tree4b57f960cf3af775d02b7eb9fe6b15cfb65a133b
parent5bc45c5e77505cc07902e6fbd99a15c9d352ded7
package/dovecot: security bump to version 2.3.5.2

Fixes the following security issue:

* CVE-2019-10691: Trying to login with 8bit username containing
  invalid UTF8 input causes auth process to crash if auth policy is
  enabled. This could be used rather easily to cause a DoS. Similar
  crash also happens during mail delivery when using invalid UTF8 in
  From or Subject header when OX push notification driver is used.

https://dovecot.org/pipermail/dovecot-news/2019-April/000406.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/dovecot/dovecot.hash
package/dovecot/dovecot.mk