[Git][security-tracker-team/security-tracker][master] dovecot references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 11:55:00 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7ca7de18 by Moritz Muehlenhoff at 2026-09-24T12:54:39+02:00
dovecot references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -32499,12 +32499,15 @@ CVE-2026-40017 (An attacker that can send mail to a user can craft a message hea
CVE-2026-40015 (An attacker that has valid credentials can open many connections to th ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40015-imap-hibernate-can-be-crashed
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/caeee3d1d2b725963555fe63ea8200292cad1058
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/09f7a34a6a9888d1325524ff8095d0a7793c075f
CVE-2026-40014 (An attacker that can send mail to a user can craft a message header th ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40014-imap-thread-references-o-n2-cpu-dos-via-crafted-references-header-index-thread-links-c
CVE-2026-40013 (An attacker that has valid credentials can submit a Sieve script conta ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40013-pigeonhole-stack-buffer-underflow-in-pigeonhole-managesieve-checkscript-putscript
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/ebbf9fe427aa4f3c543abd4ef80564ff173856bc
CVE-2026-3423 (The Envira Gallery plugin for WordPress is vulnerable to Stored Cross- ...)
NOT-FOR-US: WordPress plugin
CVE-2026-38725 (xipblog module v2.0.1 and before for PrestaShop allows unauthenticated ...)
@@ -32531,6 +32534,7 @@ CVE-2026-37236 (grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control.
CVE-2026-33607 (An attacker that has valid credentials can use IMAP LIST command to co ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33607-dovecot-imap-list-match-sub-exponential-backtracking-%E2%80%94-cpu-denial-of-service
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/2684624bb68ebbd440dab4d64d0b8be9ef5ea5aa
CVE-2026-33606 (Mail content stored by a user can be crafted so that it is interpreted ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33606-dsync-mail-content-can-cause-dsync-protocol-injection
@@ -32542,10 +32546,13 @@ CVE-2026-33605 (An unauthenticated attacker can crash the ManageSieve login proc
CVE-2026-33604 (An attacker that can get Dovecot to relay a message, for example throu ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33604-smtp-smuggling-via-missing-dot-stuffing-after-bare-carriage-return
- NOTE: Incomplete list of patches, not all landed in git yet
NOTE: Fixed by: https://github.com/dovecot/core/commit/e94a6c3cb984f9d1e5fe51714ea5015205d79fd1
NOTE: Fixed by: https://github.com/dovecot/core/commit/4677492d038f5187363790b5a93bd5fccc989a98
NOTE: Fixed by: https://github.com/dovecot/core/commit/8f04979a7e72d3b3e04f3a93bd8088f5e2332dd9
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/eeeba5dee9c3fab3be595178de6c1352677e8489
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/02dfc4c970d7b5b6093ec0551aae727ddc8c1453
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/1da3e4dc88388bb818bcb73610489249e2458353
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/6e7860f07e11441d2a2e1c00f5f043d0a565b262
CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached, subm ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33263-submission-login-panic-when-mail-max-userip-connections-is-reached-panic-epoll-ctl-del-8-failed-bad-file-descriptor
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ca7de18aa12f55e5948f4c41c17f7dcb4bcec7d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ca7de18aa12f55e5948f4c41c17f7dcb4bcec7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/644c9f36/attachment.htm>
More information about the debian-security-tracker-commits
mailing list