[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Add commits for CVE-2017-14461/dovecot
Salvatore Bonaccorso
carnil at debian.org
Thu Mar 1 06:37:57 UTC 2018
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cebde0c7 by Salvatore Bonaccorso at 2018-03-01T07:37:37+01:00
Add commits for CVE-2017-14461/dovecot
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -28419,10 +28419,17 @@ CVE-2017-14463
RESERVED
CVE-2017-14462
RESERVED
-CVE-2017-14461
+CVE-2017-14461 [rfc822_parse_domain information leak vulnerability]
RESERVED
- dovecot <unfixed>
NOTE: https://www.dovecot.org/list/dovecot-news/2018-February/000370.html
+ NOTE: https://github.com/dovecot/core/commit/30dc856f7b97b75b0e0d69f5003d5d99a13249b4
+ NOTE: https://github.com/dovecot/core/commit/8d65e2345e1dbedb00b662ee0abd05be2e7e6b7e
+ NOTE: https://github.com/dovecot/core/commit/b72d864b8c34cb21076214c0b28101baec530141
+ NOTE: https://github.com/dovecot/core/commit/e9b86842441a668b30796bff7d60828614570a1b
+ NOTE: https://github.com/dovecot/core/commit/f5cd17a27f0b666567747f8c921ebe1026970f11
+ NOTE: https://github.com/dovecot/core/commit/18a7a161c8dae6f630770a3cbab7374a0c3dd732
+ NOTE: https://github.com/dovecot/core/commit/0ed696987e5e5d44e971da2a10f6275b276ece34
CVE-2017-14460 (An exploitable overly permissive cross-domain (CORS) whitelist ...)
- parity <itp> (bug #890550)
CVE-2017-14459
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/cebde0c7aa1affba6791dc0ae3f64c286f462d1a
---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/cebde0c7aa1affba6791dc0ae3f64c286f462d1a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180301/82efbcc7/attachment-0001.html>
More information about the Secure-testing-commits
mailing list