ELSA-2008-0297

ELSA-2008-0297 - dovecot security and bug fix update

Type:SECURITY
Impact:LOW
Release Date:2008-05-30

Description


[1.0.7-2]
- LDAP+auth cache user login mixup (CVE-2007-6598, #427575)
- insecure mail_extra_groups option (CVE-2008-1199, #436927)

[1.0.7-1]
- update to latest upstream, fixes a few bugs (#331441, #245249), plus two
security vulnerabilities (CVE-2007-2231, CVE-2007-4211)
- increased default login_process_size to 64 (#253363)


Related CVEs


CVE-2007-6598
CVE-2007-2231
CVE-2007-4211
CVE-2008-1199

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 5 (i386) dovecot-1.0.7-2.el5.src.rpm1cde580dbdc50447fa034db3a1a5211cd1a776ab684a6e2b691aaa0eabe754daELEA-2014-1898el5_u2_i386_base
dovecot-1.0.7-2.el5.i386.rpm913359ca5b46357502598f2b4fb12db4cceb379fa93d52d63430187b34d6d525ELEA-2014-1898el5_u2_i386_base
Oracle Linux 5 (x86_64) dovecot-1.0.7-2.el5.src.rpm1cde580dbdc50447fa034db3a1a5211cd1a776ab684a6e2b691aaa0eabe754daELEA-2014-1898el5_u2_x86_64_base
dovecot-1.0.7-2.el5.x86_64.rpm146a0c5ea5be81040a7fa7b41db467e239343c65c3f30092eb95d995a1bd7e84ELEA-2014-1898el5_u2_x86_64_base



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete