[Secure-testing-commits] r50548 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Mon Apr 10 19:42:58 UTC 2017


Author: carnil
Date: 2017-04-10 19:42:58 +0000 (Mon, 10 Apr 2017)
New Revision: 50548

Modified:
   data/CVE/list
Log:
Add CVE-2017-2669/dovecot

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-04-10 19:36:12 UTC (rev 50547)
+++ data/CVE/list	2017-04-10 19:42:58 UTC (rev 50548)
@@ -13991,8 +13991,12 @@
 	NOTE: Fixed by: https://git.kernel.org/linus/43a6684519ab0a6c52024b5e25322476cabad893
 CVE-2017-2670
 	RESERVED
-CVE-2017-2669
+CVE-2017-2669 [auth: Do not double-expand key in passdb dict when authenticating]
 	RESERVED
+	- dovecot <unfixed>
+	[wheezy] - dovecot <not-affected> (Vulnerable code not present)
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/000030feb7a30f193197f1aab8a7b04a26b42735
+	NOTE: Introduced by: https://github.com/dovecot/core/commit/79042f8c2ec1778528584c064b164d1ebcdde16b
 CVE-2017-2668
 	RESERVED
 CVE-2017-2667




More information about the Secure-testing-commits mailing list