[Git][security-tracker-team/security-tracker][master] CVE-2026-67194/LTS

Bastien Roucariès (@rouca) rouca at debian.org
Tue Aug 4 14:43:10 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c94e069d by Bastien Roucariès at 2026-08-04T15:42:48+02:00
CVE-2026-67194/LTS

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4323,7 +4323,10 @@ CVE-2026-67201 (V through 0.5.2, fixed in commit 85859f0, contains a server-side
 	- vlang <itp> (bug #1081840)
 CVE-2026-67194 (Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow a ...)
 	- courier 2.0.3-1
+	[bookworm] - courier <postponed> (Minor issue; DoS; need authentificated user)
+	[bullseye] - courier <postponed> (Minor issue; DoS; need authentificated user)
 	NOTE: Fixed by: https://github.com/svarshavchik/courier-libs/commit/b5b5581aabea3efadf5e2944947ff0214aa3533e
+	NOTE: Need authentificated user
 CVE-2026-67193 (Xlight FTP Server before 3.9.5 contains an information disclosure vuln ...)
 	NOT-FOR-US: Xlight FTP Server
 CVE-2026-67192 (Xlight FTP Server before 3.9.5 contains a pre-authentication stack buf ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c94e069d7731838cee7b789dc0d5364dc30a01dd

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c94e069d7731838cee7b789dc0d5364dc30a01dd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/6d26c240/attachment.htm>


More information about the debian-security-tracker-commits mailing list