[Git][security-tracker-team/security-tracker][master] first batch of dovecot commit references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 23 22:55:28 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b11a4b99 by Moritz Muehlenhoff at 2026-09-23T23:54:57+02:00
first batch of dovecot commit references
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -31603,6 +31603,20 @@ CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached
CVE-2026-27852 (An attacker that can send mail to a user can craft a message whose hea ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-27852-dos-by-sending-mail-with-bad-header
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/035fbfa155288ac037965e0e4700eb198ccbf39a (2.4.3)
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/4380d7c5293760c0473566a227c63f3f91304f90
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/8f0089e5a811d7ee46eff17e2a46de7e004a74f4
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/ec0294808ea6443690044132c5f309ed0272cc06
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/977de721d6fcac09ab254958253856abcc0393c1
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/f27b7ae04f88f662c5f2bdd256ee9bef86d4c937
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/00daee1af18d929b3fcd14aa52840e38fe929711
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/41c4a77d2830a70616273962c720b7e2a9041efa
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/a81dd72a884a4f3e6b2859e9dd4fbada8c3900fe
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/84e6d207c83e9c1ed1d533d591475d9da2d6b55b
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/4b7e869b4b8fb70e0c32e4106aebc31a07b9f75b
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/c853685f820157046136bd027861cb2a21c13fbc
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/32010a7067a7970d302981c888f1e10904184499
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/1fa4c5a3fe21ca1994e54022050d23e260416c3c
CVE-2026-19423 (The Ultimate Member WordPress plugin before 2.13.0 does not validate ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19412 (This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to th ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -32,7 +32,7 @@ containerd
--
cups
--
-dovecot
+dovecot (jmm)
--
dulwich
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b11a4b99c03b9cceb0e3c47378cf96991afe047a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b11a4b99c03b9cceb0e3c47378cf96991afe047a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/2c1d889f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list