[Git][security-tracker-team/security-tracker][master] dovecot commit references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 08:52:48 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e4a3371b by Moritz Muehlenhoff at 2026-09-24T09:52:28+02:00
dovecot commit references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -32490,9 +32490,15 @@ CVE-2026-33606 (Mail content stored by a user can be crafted so that it is inter
CVE-2026-33605 (An unauthenticated attacker can crash the ManageSieve login process by ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33605-managesieve-login-pre-auth-crash
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/14c28ca9c4aab11b1074c629bb744c4741434148
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/77bf1049ab8652b125e02ed00a15e1dd2e1feb98
CVE-2026-33604 (An attacker that can get Dovecot to relay a message, for example throu ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33604-smtp-smuggling-via-missing-dot-stuffing-after-bare-carriage-return
+ NOTE: Incomplete list of patches, not all landed in git yet
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/e94a6c3cb984f9d1e5fe51714ea5015205d79fd1
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/4677492d038f5187363790b5a93bd5fccc989a98
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/8f04979a7e72d3b3e04f3a93bd8088f5e2332dd9
CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached, subm ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33263-submission-login-panic-when-mail-max-userip-connections-is-reached-panic-epoll-ctl-del-8-failed-bad-file-descriptor
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4a3371befb5e033d4c34c1a0c720c3f4f41dc83
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4a3371befb5e033d4c34c1a0c720c3f4f41dc83
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/5a7501dd/attachment.htm>
More information about the debian-security-tracker-commits
mailing list