From f79e8e7e4d1cf4d7ca177a81f2061df8ee416848 Mon Sep 17 00:00:00 2001 From: Aki Tuomi Date: Tue, 5 Feb 2019 09:18:41 +0200 Subject: [PATCH] Released v2.3.4.1 --- NEWS | 13 +++++++++++++ configure.ac | 2 +- 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/NEWS b/NEWS index f33af3476d..8129537920 100644 --- a/NEWS +++ b/NEWS @@ -1,3 +1,16 @@ +v2.3.4.1 2019-02-05 Aki Tuomi + + * CVE-2019-3814: If imap/pop3/managesieve/submission client has + trusted certificate with missing username field + (ssl_cert_username_field), under some configurations Dovecot + mistakenly trusts the username provided via authentication instead + of failing. + * ssl_cert_username_field setting was ignored with external SMTP AUTH, + because none of the MTAs (Postfix, Exim) currently send the + cert_username field. This may have allowed users with trusted + certificate to specify any username in the authentication. This bug + didn't affect Dovecot's Submission service. + v2.3.4 2018-11-23 Timo Sirainen * The default postmaster_address is now "postmaster@