dovecot: IMAP and POP3 Server Written Primarily with Security in Mind ---------------------------------------------------------------------- File: dovecot-1.0.rc14-11.x86_64.rpm Patchrpm: dovecot-1.0.rc14-11.x86_64.patch.rpm Version: 1.0.rc14-11 Size: 1579 kB Patchsize: 1196 kB Date: Mon 29 Sep 2008 17:15:20 CEST Source: dovecot-1.0.rc14-11.src.rpm Security: Yes ---------------------------------------------------------------------- Description: When configured with 'mail_extra_groups' dovecot potentially allowed users to read mail boxes of other users. This is not the case in the default configuration of on openSUSE (CVE-2008-1199). By using tab characters in passwords remote attackers could potentially acquire unauthorized access (CVE-2008-1218). Flaws in caching LDAP data could lead to users getting logged in with the wrong account (CVE-2007-6598).