ELSA-2009-0205

ELSA-2009-0205 - dovecot security and bug fix update

Type:SECURITY
Impact:LOW
Release Date:2009-01-27

Description


[1.0.7-7]
- permissions of deliver and dovecot.conf from 1.0.7-5 reverted
- password can be stored in different file readable only for root now
- Resolves: #436287, CVE-2008-4870

[1.0.7-6]
- added missing directory in file list
- Resolves: #436287

[1.0.7-5]
- change permissions of deliver and dovecot.conf to prevent possible password ex
posure
- Resolves: #436287

[1.0.7-4]
- fix handling of negative rights in the ACL plugin
- Resolves: #469015, CVE-2008-4577

[1.0.7-3]
- fix package ownership for /etc/pki/dovecot/private (#448089)
- update init script (#238016)
- ask for SSL cert password during start-up (#436287)
- fix for illegal characters in passwd (#439369)
- Resolves: #448089, #238016, #436287, #439369


Related CVEs


CVE-2008-4577
CVE-2008-4870

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 5 (i386) dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898el5_u3_i386_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898el5_u4_i386_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898el5_u5_i386_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898ol5_i386_latest
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898ol5_u6_i386_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898ol5_u7_i386_base
dovecot-1.0.7-7.el5.i386.rpm37e50a6e454c8e4d52e2cccd6e1dbfb4f717826c4fa4ec32bb3d00ab0e1dce38ELEA-2014-1898el5_u3_i386_base
dovecot-1.0.7-7.el5.i386.rpm37e50a6e454c8e4d52e2cccd6e1dbfb4f717826c4fa4ec32bb3d00ab0e1dce38ELEA-2014-1898el5_u4_i386_base
dovecot-1.0.7-7.el5.i386.rpm37e50a6e454c8e4d52e2cccd6e1dbfb4f717826c4fa4ec32bb3d00ab0e1dce38ELEA-2014-1898el5_u5_i386_base
dovecot-1.0.7-7.el5.i386.rpm37e50a6e454c8e4d52e2cccd6e1dbfb4f717826c4fa4ec32bb3d00ab0e1dce38ELEA-2014-1898ol5_i386_latest
dovecot-1.0.7-7.el5.i386.rpm37e50a6e454c8e4d52e2cccd6e1dbfb4f717826c4fa4ec32bb3d00ab0e1dce38ELEA-2014-1898ol5_u6_i386_base
dovecot-1.0.7-7.el5.i386.rpm37e50a6e454c8e4d52e2cccd6e1dbfb4f717826c4fa4ec32bb3d00ab0e1dce38ELEA-2014-1898ol5_u7_i386_base
Oracle Linux 5 (ia64) dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898el5_u4_ia64_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898el5_u5_ia64_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898ol5_ia64_latest
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898ol5_u6_ia64_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898ol5_u7_ia64_base
dovecot-1.0.7-7.el5.ia64.rpmad4594d78423fd594e084647b2e2538ba0a5908cacb0a7bb0de89268df499081ELEA-2014-1898el5_u4_ia64_base
dovecot-1.0.7-7.el5.ia64.rpmad4594d78423fd594e084647b2e2538ba0a5908cacb0a7bb0de89268df499081ELEA-2014-1898el5_u5_ia64_base
dovecot-1.0.7-7.el5.ia64.rpmad4594d78423fd594e084647b2e2538ba0a5908cacb0a7bb0de89268df499081ELEA-2014-1898ol5_ia64_latest
dovecot-1.0.7-7.el5.ia64.rpmad4594d78423fd594e084647b2e2538ba0a5908cacb0a7bb0de89268df499081ELEA-2014-1898ol5_u6_ia64_base
dovecot-1.0.7-7.el5.ia64.rpmad4594d78423fd594e084647b2e2538ba0a5908cacb0a7bb0de89268df499081ELEA-2014-1898ol5_u7_ia64_base
Oracle Linux 5 (x86_64) dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898el5_u3_x86_64_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898el5_u4_x86_64_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898el5_u5_x86_64_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898ol5_u6_x86_64_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898ol5_u7_x86_64_base
dovecot-1.0.7-7.el5.src.rpm9415c0bac1793b7727e23c35ad4c8eab3fe09d7a81f095354c4f51c913cd314eELEA-2014-1898ol5_x86_64_latest
dovecot-1.0.7-7.el5.x86_64.rpmf2d2f636b0d3ab8a77c2b9bebc1c2d0af53983976ad3ef8898021998dff7c68dELEA-2014-1898el5_u3_x86_64_base
dovecot-1.0.7-7.el5.x86_64.rpmf2d2f636b0d3ab8a77c2b9bebc1c2d0af53983976ad3ef8898021998dff7c68dELEA-2014-1898el5_u4_x86_64_base
dovecot-1.0.7-7.el5.x86_64.rpmf2d2f636b0d3ab8a77c2b9bebc1c2d0af53983976ad3ef8898021998dff7c68dELEA-2014-1898el5_u5_x86_64_base
dovecot-1.0.7-7.el5.x86_64.rpmf2d2f636b0d3ab8a77c2b9bebc1c2d0af53983976ad3ef8898021998dff7c68dELEA-2014-1898ol5_u6_x86_64_base
dovecot-1.0.7-7.el5.x86_64.rpmf2d2f636b0d3ab8a77c2b9bebc1c2d0af53983976ad3ef8898021998dff7c68dELEA-2014-1898ol5_u7_x86_64_base
dovecot-1.0.7-7.el5.x86_64.rpmf2d2f636b0d3ab8a77c2b9bebc1c2d0af53983976ad3ef8898021998dff7c68dELEA-2014-1898ol5_x86_64_latest



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete