Browse Source

[Dovecot] Fixes CVE-2017-15132

andre.peters 7 years ago
parent
commit
6ebcd00521
2 changed files with 2 additions and 1 deletions
  1. 1 0
      data/Dockerfiles/dovecot/Dockerfile
  2. 1 1
      docker-compose.yml

+ 1 - 0
data/Dockerfiles/dovecot/Dockerfile

@@ -65,6 +65,7 @@ RUN apt-get update && apt-get -y --no-install-recommends install \
 
 RUN curl https://www.dovecot.org/releases/2.2/dovecot-$DOVECOT_VERSION.tar.gz | tar xvz  \
   && cd dovecot-$DOVECOT_VERSION \
+  && sed '/call_callback(request, AUTH_REQUEST_STATUS_ABORT, NULL, NULL);/a   pool_unref(&request->pool);' src/lib-auth/auth-client-request.c \
   && ./configure --with-mysql --with-lzma --with-lz4 --with-ssl=openssl --with-notify=inotify --with-storages=mdbox,sdbox,maildir,mbox,imapc,pop3c --with-bzlib --with-zlib \
   && make -j3 \
   && make install \

+ 1 - 1
docker-compose.yml

@@ -148,7 +148,7 @@ services:
             - sogo
 
     dovecot-mailcow:
-      image: mailcow/dovecot:1.18
+      image: mailcow/dovecot:1.19
       build: ./data/Dockerfiles/dovecot
       cap_add:
         - NET_BIND_SERVICE