[PATCH 6/6] imap: Reset DEFLATE dictionary after every tagged reply
Prevents CRIME-style cross-command compression oracle attacks
(CVE-class: compression side-channel). Without this fix an observer
who can inject chosen plaintext into one IMAP command's response can
measure the compressed size of a subsequent command's response and
determine whether the secret content matches the injected plaintext.
After each tagged response line is sent, the DEFLATE compression
dictionary is reset via Z_FULL_FLUSH so that the compression history
from one command cannot influence the compressed size of the next.
For direct compression (imap_compress_on_proxy=no) the reset is applied
to the local ostream. For proxy-mode compression
(imap_compress_on_proxy=yes) a "dict_reset" command is sent over the
multiplex side channel to the imap-login process.
Gbp-Pq: Name 0006-imap-Reset-DEFLATE-dictionary-after-every-tagged-rep.patch