[Git][security-tracker-team/security-tracker][master] dovecot references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 13:10:10 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
802839f5 by Moritz Muehlenhoff at 2026-09-24T14:09:47+02:00
dovecot references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -32536,6 +32536,18 @@ CVE-2026-40018 (None None None No publicly available exploits are known.)
CVE-2026-40017 (An attacker that can send mail to a user can craft a message header wh ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40017-imap-thread-o-m3-cpu-dos-via-crc32-hash-collision-in-strmap-mail-index-strmap-c-hash2-c
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/d3e1c7fb5845f68d84aa04d941b8116048b06195
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/15689cf2cd9f078cb52187568fe7086ecf0a00b2
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/a028002fcf7d3571e043206229950fed5245b4fe
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/886c06d1c46eb162af29c3d4653df91c4da3ee8d
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/8d4ff69d4a40d1073946823cd0f7c1d937f51aee
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/ec847941fd1d958b03d5578060abd294b1dc3cf8
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/fed5164930daf472fbb759096037efd5e7ee8468
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/03bd8a3d2c2783ab3bb6ab79eab9a2fc3609a6a6
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/3612c5ed51acb43c8142713c64cad6cc4234d4d6
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/1a02e74b03cbd298ca4d863735650cc13304513b
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/4d886f42e4524ed4df27042e33546512f3fe20cf
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/8fedf386644e979f731854e53aa2e26d599776a5
CVE-2026-40015 (An attacker that has valid credentials can open many connections to th ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40015-imap-hibernate-can-be-crashed
@@ -32544,6 +32556,9 @@ CVE-2026-40015 (An attacker that has valid credentials can open many connections
CVE-2026-40014 (An attacker that can send mail to a user can craft a message header th ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40014-imap-thread-references-o-n2-cpu-dos-via-crafted-references-header-index-thread-links-c
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/113eac6cbbae1bf292e7dd1826eede3f929fe6c9
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/ad92d716328c646e4dcd4dd2aaa14bc3e422eb8d
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/f4e7474bdb5e7557ea3d985f9f27ef8d7f91ad68
CVE-2026-40013 (An attacker that has valid credentials can submit a Sieve script conta ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40013-pigeonhole-stack-buffer-underflow-in-pigeonhole-managesieve-checkscript-putscript
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/802839f54c562d5c167671e8195533b64adcad5b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/802839f54c562d5c167671e8195533b64adcad5b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/4b8a3412/attachment.htm>
More information about the debian-security-tracker-commits
mailing list