cyrus-imapd security update
cyrus-imapd recognized commands before switching to an
encrypted channel via STARTTLS. Attackers could potentially
exploit that to inject plain text commands (CVE-2011-1926).
-
Submitted by
Adrian Schröter (adrianSuSE)
- Version 4736
Fixed bugs
bnc#694247
VUL-0: cyrus-imapd: STARTTLS issue