| 20 Jun 2021 |
hexa | and v5.4.124 | 22:09:13 |
| 21 Jun 2021 |
| emily joined the room. | 00:35:35 |
| industrialrobot joined the room. | 08:12:49 |
ajs124 | seems like there was a dovecot + pigeonhole security release just now | 11:50:21 |
das_j | changelog says:
* CVE-2021-29157: Dovecot does not correctly escape kid and azp fields in
JWT tokens. This may be used to supply attacker controlled keys to
validate tokens, if attacker has local access.
* CVE-2021-33515: On-path attacker could have injected plaintext commands
before STARTTLS negotiation that would be executed after STARTTLS
finished with the client.
| 11:51:49 |
hexa | ajs124: das_j are you taking care of that? | 13:07:05 |
das_j | I think ajs124 is currently on it | 13:07:24 |
hexa | I hope he knows that as well | 13:07:49 |
das_j | He told me so - so he might know but who am I to tell | 13:08:53 |
dotlambda | In pigeonhole, the following was fixed: CVE-2020-28200: Sieve excessive resource usage. But I'm not sure version 0.5.15 can be used with earlier versions of Dovecot, so what do we do on stable? | 13:12:46 |
ajs124 | dotlambda: backport? | 13:18:13 |
ajs124 | there's also 2.3.14.1, maybe that works with the new dovecot? | 13:18:24 |
ajs124 | * there's also 2.3.14.1, maybe that works with the new pigeonhole? | 13:18:28 |
dotlambda | I'm gonna ask on IRC | 13:18:37 |
ajs124 | https://github.com/NixOS/nixpkgs/pull/127667 | 13:24:27 |
ajs124 | andi-: aren't you a dovecot user? if so, do you maybe have some time to review ⬆️? | 14:37:45 |
andi- | I can't test right now. Only gonna be back home on sunday. | 14:39:23 |
das_j | ajs124: You can test on mail02 | 14:39:38 |
das_j | Isn't there a dovecot? | 14:39:47 |
ajs124 | I can also test on mail01 🤷♂️ | 14:40:01 |
das_j | I do hereby explicitly not approve of this | 14:40:16 |
ajs124 |
Active: active (running) since Mon 2021-06-21 16:35:54 CEST; 4min 29s ago
| 14:40:31 |
ajs124 | * Active: active (running) since Mon 2021-06-21 16:35:54 CEST; 4min 29s ago
CGroup: /system.slice/dovecot2.service
├─2666908 /nix/store/cmh9cnp6ng654xkb0la6yk9hsrniaqmd-dovecot-2.3.15/sbin/dovecot -F
| 14:40:54 |
hexa | doesn't crash, okay. but does it also work? | 14:41:06 |
ajs124 | it throws the same error messages as in the previous release? | 14:41:26 |
hexa | awesome | 14:41:34 |
ajs124 | we even still have the systemd unit that isn't used by the module (I think) in the package | 14:43:13 |
Ekleog | Redacted or Malformed Event | 14:52:54 |
Ekleog | Redacted or Malformed Event | 14:53:33 |
Ekleog | Redacted or Malformed Event | 14:54:20 |