[Git][security-tracker-team/security-tracker][master] dovecot references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 15:27:06 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bd07c304 by Moritz Muehlenhoff at 2026-09-24T16:26:38+02:00
dovecot references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -32505,6 +32505,18 @@ CVE-2026-52687 (An attacker that has valid credentials can select a compression
CVE-2026-52681 (Sieve CPU resource usage is tracked in the compiled script, so an atta ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52681-sieve-resource-usage-tracking-lost-when-active-script-changes
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/8d52bc7d037cda5f27fe996511a5367752095812
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/0ea42d6620746132c10f7a6ce4262dbbccf12751
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/d82c2e624e4a9c364a6fa58fad0938ae5578660c
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/4d0cbfe6260d567ebc34a747c29bb4e140124d93
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/d6ba245e6ea6b062cd29f90cd4400e1865c711bc
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/a6e8a540d5dfbd74c8397861a4df0224c857c83f
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/62c759f78aa305c7aac7ea4733ea3c21a4059865
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/d40ae7f5f55262bf8d210400da8a48523eb87ceb
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/9b53f677825589c0334365aa0d165abf90175648
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/3f62d49c50f182e467972ccecdd340ec178f8dba
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/64b37c84373690d65e28fb5f45453612c260e4c8
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/f65a341b027442d4448da039b8c623dcb69c37aa
CVE-2026-50979 (A command injection vulnerability in the 'advanced/curl' component of ...)
NOT-FOR-US: Osbil Technology oPanel
CVE-2026-4378 (Improper neutralization of input during web page generation ('cross-si ...)
@@ -32520,6 +32532,7 @@ CVE-2026-42393 (The comparison used for the doveadm password and API key is not
CVE-2026-42392 (An attacker that has valid credentials can send an invalid IMAP URLFET ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42392-imap-urlauth-leaks-memory-into-user-visible-error-messages
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/48d8141049f7150a0469a4efe68669fbf8bcbb24
CVE-2026-42391 (An unauthenticated attacker can send an IMAP ID command with a very la ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42391-imap-pre-login-memory-cpu-growth-with-id-command
@@ -32629,6 +32642,8 @@ CVE-2026-33607 (An attacker that has valid credentials can use IMAP LIST command
CVE-2026-33606 (Mail content stored by a user can be crafted so that it is interpreted ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33606-dsync-mail-content-can-cause-dsync-protocol-injection
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/bd707cab9decd4a069c9cdfd3e28d28cf9346fdd
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/7d782e5f5e51f63483393a460594d6a8f920b6d6
CVE-2026-33605 (An unauthenticated attacker can crash the ManageSieve login process by ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33605-managesieve-login-pre-auth-crash
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd07c304aec9d56e52f265a93ec1e4b5ef519a8c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd07c304aec9d56e52f265a93ec1e4b5ef519a8c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/1888dbc4/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list