[Git][security-tracker-team/security-tracker][master] dovecot references

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 14:26:27 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
76c9f423 by Moritz Muehlenhoff at 2026-09-24T15:26:06+02:00
dovecot references

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -32461,6 +32461,10 @@ CVE-2026-73209 (An attacker that has valid credentials can send crafted compress
 CVE-2026-73208 (An attacker that holds a token intended for a different purpose can au ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73208-auth-db-oauth2-aud-claim-used-as-fallback-for-missing-scope-claim
+	NOTE: Same fixes for CVE-2026-40205 and CVE-2026-73208
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/4aa93054b6c9e4d0503e1cb78be36b389d2af98c
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/8518e3f62183b462bef645977b48af32e6701f6f
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/91b7a86a20f805301e8ea15715b246040c4d8cd9
 CVE-2026-6286 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-6176 (The Customer Reviews for WooCommerce plugin for WordPress is vulnerabl ...)
@@ -32519,11 +32523,18 @@ CVE-2026-42008 (Forwarding information received from a host listed as a trusted
 CVE-2026-42007 (An attacker that has valid credentials can use a Sieve script with the ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42007-sieve-editheader-rce
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/69bac9cd6d4ac09100ee50c98052be1437f1da29
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/cd9870e7f87e9d91e9d05b402da653df845b4f8f
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/a44ba381619a06416ce3f34eae9765de46ece5d9
 CVE-2026-40541 (An improper neutralization of input during web page generation ('Cross ...)
 	NOT-FOR-US: Synology
 CVE-2026-40205 (An attacker that holds an OAuth2 token granting only part of the requi ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40205-oauth2-passdb-scope-enforcement-bypass-via-or-semantics-in-remote-validation-path
+	NOTE: Same fixes for CVE-2026-40205 and CVE-2026-73208
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/4aa93054b6c9e4d0503e1cb78be36b389d2af98c
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/8518e3f62183b462bef645977b48af32e6701f6f
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/91b7a86a20f805301e8ea15715b246040c4d8cd9
 CVE-2026-40204 (None None None No publicly available exploits are known.)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40204-acl-lda-mailbox-autocreate-can-bypass-acl-restrictions
@@ -32536,6 +32547,16 @@ CVE-2026-40019 (An unauthenticated attacker can send a truncated quoted argument
 CVE-2026-40018 (None None None No publicly available exploits are known.)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40018-mysql-multi-byte-escaping-wrong
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/a78c015eae67a891a0c14b5434dd1f99838ae4cc
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/7aa8c147eb15009b56c85a00c33c2c0b972c1398
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/4190313f6c4945377341017abc50e5239464627c
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/710765b420277a6abd7ce9276f7520dcbdf91567
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/cf4543ce91058e81daf02b5c3cf8984cc98785b3
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/ff926d0c9288f343d18a3c9ec20cf1e252d52286
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/98282f1a02d29d6fdd0b3db63ae398d0162fe7bd
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/c1a03b211f368d6463eaf9527da9058b0fdc44b5
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/ec4cbb78314dc46e77a2abab205969d80708d5f2
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/d3a4d4fc2d2c84403df6eea0da1c4b7bd1d887da
 CVE-2026-40017 (An attacker that can send mail to a user can craft a message header wh ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40017-imap-thread-o-m3-cpu-dos-via-crc32-hash-collision-in-strmap-mail-index-strmap-c-hash2-c



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/76c9f4235c64bb55ba513346d028f1ed4a4902a8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/76c9f4235c64bb55ba513346d028f1ed4a4902a8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/c86fa57d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list