Results 1 to 3 of 3

Thread: Dovecot 2.3.4.1 (CVE)

  1. #1
    Join Date
    Sep 2015
    Location
    Arnhem, NL
    Posts
    427

    Lightbulb Dovecot 2.3.4.1 (CVE)

    Dovecot:

    v2.3.4.1
    &
    v2.2.36.1

    have been released, containing CVE and bug fixes.

    https://www.dovecot.org/list/dovecot...ry/000394.html

  2. #2
    Join Date
    May 2008
    Posts
    817
    And FreeBSD users are with no luck once again:

    https://www.mail-archive.com/dovecot.../msg75964.html

    Either apply the patch manually or... wait for 2.3.5

    The patch is:

    https://github.com/dovecot/core/comp...de42b54a.patch
    Last edited by wattie; 02-09-2019 at 03:08 PM.

  3. #3
    Join Date
    May 2008
    Posts
    817
    Here is how I patched it. I opened two consoles. I'll name them "A" and "B". So starting in "A" I did:

    A> ./build update
    A> ./build dovecot

    and it failed and hung on a message saying if you want to try the make again. Leave it like that and go to console B:

    B> cd /usr/local/directadmin/custombuild/dovecot-2.3.4.1/src
    B> wget https://github.com/dovecot/core/comp...de42b54a.patch
    B> mv 1004822^..de42b54a.patch p.patch
    B> patch -p0 < p.patch

    It will ask you for the path of the file that you want to patch. It's listed right there - enter "./src/lib-master/test-event-stats.c" twice. Then go back to console A and hit:

    A> y

    That will compile dovecot successfully.

    I guess there is maybe a much more elegant way of doing that in DA but I don't know it

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •