Upstream information

CVE-2019-11494 at MITRE

Description

In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.

SUSE information

SUSE Bugzilla entries: 1133624 [RESOLVED / FIXED], 1133625 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Module for Server Applications 15 SP1
  • dovecot23 >= 2.3.3-8.1
  • dovecot23-backend-mysql >= 2.3.3-8.1
  • dovecot23-backend-pgsql >= 2.3.3-8.1
  • dovecot23-backend-sqlite >= 2.3.3-8.1
  • dovecot23-devel >= 2.3.3-8.1
  • dovecot23-fts >= 2.3.3-8.1
  • dovecot23-fts-lucene >= 2.3.3-8.1
  • dovecot23-fts-solr >= 2.3.3-8.1
  • dovecot23-fts-squat >= 2.3.3-8.1
Patchnames:
SUSE-SLE-Module-Server-Applications-15-SP1-2019-2514
SUSE Linux Enterprise Module for Server Applications 15 SP2
  • dovecot23 >= 2.3.10-15.1
  • dovecot23-backend-mysql >= 2.3.10-15.1
  • dovecot23-backend-pgsql >= 2.3.10-15.1
  • dovecot23-backend-sqlite >= 2.3.10-15.1
  • dovecot23-devel >= 2.3.10-15.1
  • dovecot23-fts >= 2.3.10-15.1
  • dovecot23-fts-lucene >= 2.3.10-15.1
  • dovecot23-fts-solr >= 2.3.10-15.1
  • dovecot23-fts-squat >= 2.3.10-15.1
SUSE Linux Enterprise Module for Server Applications 15 SP3
  • dovecot23 >= 2.3.11.3-17.5.1
  • dovecot23-backend-mysql >= 2.3.11.3-17.5.1
  • dovecot23-backend-pgsql >= 2.3.11.3-17.5.1
  • dovecot23-backend-sqlite >= 2.3.11.3-17.5.1
  • dovecot23-devel >= 2.3.11.3-17.5.1
  • dovecot23-fts >= 2.3.11.3-17.5.1
  • dovecot23-fts-lucene >= 2.3.11.3-17.5.1
  • dovecot23-fts-solr >= 2.3.11.3-17.5.1
  • dovecot23-fts-squat >= 2.3.11.3-17.5.1
SUSE Linux Enterprise Module for Server Applications 15
  • dovecot23 >= 2.3.3-4.18.1
  • dovecot23-backend-mysql >= 2.3.3-4.18.1
  • dovecot23-backend-pgsql >= 2.3.3-4.18.1
  • dovecot23-backend-sqlite >= 2.3.3-4.18.1
  • dovecot23-devel >= 2.3.3-4.18.1
  • dovecot23-fts >= 2.3.3-4.18.1
  • dovecot23-fts-lucene >= 2.3.3-4.18.1
  • dovecot23-fts-solr >= 2.3.3-4.18.1
  • dovecot23-fts-squat >= 2.3.3-4.18.1
Patchnames:
SUSE-SLE-Module-Server-Applications-15-2019-2516
openSUSE Leap 15.0
  • dovecot23 >= 2.3.3-lp150.14.1
  • dovecot23-backend-mysql >= 2.3.3-lp150.14.1
  • dovecot23-backend-pgsql >= 2.3.3-lp150.14.1
  • dovecot23-backend-sqlite >= 2.3.3-lp150.14.1
  • dovecot23-devel >= 2.3.3-lp150.14.1
  • dovecot23-fts >= 2.3.3-lp150.14.1
  • dovecot23-fts-lucene >= 2.3.3-lp150.14.1
  • dovecot23-fts-solr >= 2.3.3-lp150.14.1
  • dovecot23-fts-squat >= 2.3.3-lp150.14.1
Patchnames:
openSUSE-2019-2278
openSUSE Leap 15.1
  • dovecot23 >= 2.3.3-lp151.2.6.1
  • dovecot23-backend-mysql >= 2.3.3-lp151.2.6.1
  • dovecot23-backend-pgsql >= 2.3.3-lp151.2.6.1
  • dovecot23-backend-sqlite >= 2.3.3-lp151.2.6.1
  • dovecot23-devel >= 2.3.3-lp151.2.6.1
  • dovecot23-fts >= 2.3.3-lp151.2.6.1
  • dovecot23-fts-lucene >= 2.3.3-lp151.2.6.1
  • dovecot23-fts-solr >= 2.3.3-lp151.2.6.1
  • dovecot23-fts-squat >= 2.3.3-lp151.2.6.1
Patchnames:
openSUSE-2019-2281
openSUSE Tumbleweed
  • dovecot23 >= 2.3.16-1.6
  • dovecot23-backend-mysql >= 2.3.16-1.6
  • dovecot23-backend-pgsql >= 2.3.16-1.6
  • dovecot23-backend-sqlite >= 2.3.16-1.6
  • dovecot23-devel >= 2.3.16-1.6
  • dovecot23-fts >= 2.3.16-1.6
  • dovecot23-fts-lucene >= 2.3.16-1.6
  • dovecot23-fts-solr >= 2.3.16-1.6
  • dovecot23-fts-squat >= 2.3.16-1.6
Patchnames:
openSUSE Tumbleweed GA dovecot23-2.3.16-1.6