This update for dovecot23 fixes the following issues:
Update dovecot to version 2.3.15 (jsc#SLE-19970):
Security issues fixed:
CVE-2021-33515: On-path attacker could have injected plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the client. (bsc#1187419) Attacker can potentially steal user credentials and mails
Disconnection log messages are now more standardized across services. They also always now start with 'Disconnected' prefix.
Update pigeonhole to version 0.5.15
{ "binaries": [ { "dovecot23-fts-lucene": "2.3.15-58.3", "dovecot23-devel": "2.3.15-58.3", "dovecot23-backend-pgsql": "2.3.15-58.3", "dovecot23-fts": "2.3.15-58.3", "dovecot23": "2.3.15-58.3", "dovecot23-backend-sqlite": "2.3.15-58.3", "dovecot23-backend-mysql": "2.3.15-58.3", "dovecot23-fts-solr": "2.3.15-58.3", "dovecot23-fts-squat": "2.3.15-58.3" } ] }
{ "binaries": [ { "dovecot23-fts-lucene": "2.3.15-58.3", "dovecot23-devel": "2.3.15-58.3", "dovecot23-backend-pgsql": "2.3.15-58.3", "dovecot23-fts": "2.3.15-58.3", "dovecot23": "2.3.15-58.3", "dovecot23-backend-sqlite": "2.3.15-58.3", "dovecot23-backend-mysql": "2.3.15-58.3", "dovecot23-fts-solr": "2.3.15-58.3", "dovecot23-fts-squat": "2.3.15-58.3" } ] }