[Dovecot-news] CentOS 6 packages dropped

2020-08-12 Thread Aki Tuomi
Hi! We are dropping CentOS 6 packages now that we have CentOS 8 packages available. 2.3.11.3 will be last version for which CentOS 6 packages are built for https://repo.dovecot.org. Regards, Aki Tuomi Open-Xchange oy signature.asc Description: PGP signature ___

[Dovecot-news] CentOS 8 packages available

2020-08-12 Thread Aki Tuomi
We are happy to announce that we have CentOS 8 packages available starting from v2.3.11.3. You can find these packages at https://repo.dovecot.org/ Regards, Aki Tuomi Open-Xchange oy signature.asc Description: OpenPGP digital signature ___ Dovecot-new

[Dovecot-news] CVE-2020-12674: Specially crafted RPA authentication message crashes auth

2020-08-12 Thread Aki Tuomi
Open-Xchange Security Advisory 2020-08-12 Affected product: Dovecot IMAP server Internal reference: DOP-1869 (Bug ID) Vulnerability type: CWE-126 (Buffer over-read) Vulnerable version: 2.2 Vulnerable component: auth Fixed version: 2.3.11.3 Report confidence: Confirmed Solution status: Fix availabl

[Dovecot-news] CVE-2020-12673: Specially crafted NTML package can crash auth service

2020-08-12 Thread Aki Tuomi
Open-Xchange Security Advisory 2020-08-12 Affected product: Dovecot IMAP server Internal reference: DOP-1870 (Bug ID) Vulnerability type: CWE-789 (Uncontrolled Memory Allocation) Vulnerable version: 2.2 Vulnerable component: auth Fixed version: 2.3.11.3 Report confidence: Confirmed Solution status

[Dovecot-news] CVE-2020-12100: Receiving mail with deeply nested MIME parts leads to resource exhaustion.

2020-08-12 Thread Aki Tuomi
Open-Xchange Security Advisory 2020-08-12 Affected product: Dovecot IMAP server Internal reference: DOP-1849 (Bug ID) Vulnerability type: Uncontrolled recursion (CWE-674) Vulnerable version: 2.0 Vulnerable component: submission, lmtp, lda Fixed version: 2.3.11.3 Report confidence: Confirmed Soluti

[Dovecot-news] Dovecot v2.3.11.3 released

2020-08-12 Thread Aki Tuomi
We are pleased to release v2.3.11.3. Please find it from locations below: https://dovecot.org/releases/2.3/dovecot-2.3.11.3.tar.gz https://dovecot.org/releases/2.3/dovecot-2.3.11.3.tar.gz.sig Binary packages in https://repo.dovecot.org/ Docker images in https://hub.docker.com/r/dovecot/dovecot Ak

[Dovecot-news] Pigeonhole 0.5.11 released

2020-08-12 Thread Aki Tuomi
We are pleased to release pigeonhole 0.5.11. You can download it from locations below: https://pigeonhole.dovecot.org/releases/2.3/dovecot-2.3.11-pigeonhole-0.5.11.tar.gz https://pigeonhole.dovecot.org/releases/2.3/dovecot-2.3.11-pigeonhole-0.5.11.tar.gz.sig Binary packages in https://repo.dovecot