Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-1950

Опубликовано: 17 мая 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-1950: dovecot security update (MODERATE)

[1:2.3.16-2]

  • do not disable xz/lzma for now despite being deprecated

[1:2.3.16-1]

  • dovecot updated to 2.3.16, pigeonhole to 0.5.16
  • fix CVE-2021-33515 plaintext commands injection (#1980014)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

dovecot

2.3.16-2.el8

dovecot-devel

2.3.16-2.el8

dovecot-mysql

2.3.16-2.el8

dovecot-pgsql

2.3.16-2.el8

dovecot-pigeonhole

2.3.16-2.el8

Oracle Linux x86_64

dovecot

2.3.16-2.el8

dovecot-devel

2.3.16-2.el8

dovecot-mysql

2.3.16-2.el8

dovecot-pgsql

2.3.16-2.el8

dovecot-pigeonhole

2.3.16-2.el8

Связанные CVE

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVSS3: 4.2
redhat
больше 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVSS3: 4.8
nvd
больше 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVSS3: 4.8
msrc
около 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVSS3: 4.8
debian
больше 4 лет назад

The submission service in Dovecot before 2.3.15 allows STARTTLS comman ...