cyrus-imapd security update

cyrus-imapd recognized commands before switching to an
encrypted channel via STARTTLS. Attackers could potentially
exploit that to inject plain text commands (CVE-2011-1926).

Fixed bugs
bnc#694247
VUL-0: cyrus-imapd: STARTTLS issue
CVE#CVE-2011-1926
The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in pl
Selected Binaries
openSUSE Build Service is sponsored by