[Git][security-tracker-team/security-tracker][master] dovecot references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 16:02:26 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1caacffe by Moritz Muehlenhoff at 2026-09-24T17:01:29+02:00
dovecot references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -32481,6 +32481,15 @@ CVE-2026-73827 (SOY Calendar contains a cross-site scripting vulnerability. An a
CVE-2026-73209 (An attacker that has valid credentials can send crafted compressed dat ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73209-imap-login-crash-self-recursion-on-zero-output-decompress-chunks
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/d0559b33adf1470547b6ee6ea7a82903296c5f69
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/1567b9f98db64d9a90c24925f19b48cfd59a0f1b
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/86aba25a1159f7ff11480feec287647be78054d1
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/f269b3d3051044aec31cef888fcf4c9ddd21c227
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/cac140a9e4e12485bde4348b8a8c94a7a96a6e5e
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/09df3b5b8b970439ab6b1b617b344a21cb2c07fe
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/351a30e80ce690fcefd458624a6c14c3aa514dca
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/e9eb23933949f8cbdd13282071169dc89876c139
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/f740e63144970ee36d3ca6d38e52b81d405c6f67
CVE-2026-73208 (An attacker that holds a token intended for a different purpose can au ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-73208-auth-db-oauth2-aud-claim-used-as-fallback-for-missing-scope-claim
@@ -32586,6 +32595,10 @@ CVE-2026-40204 (None None None No publicly available exploits are known.)
CVE-2026-40203 (When IMAP compression is enabled, the same compression state is reused ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40203-imap-compression-can-reveal-whether-a-small-synced-email-body-matches-sender-chosen-text
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/34787cb86a0147d987ab821772d310faab048ba6
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/c7d4e41586ac8049839529ab20f36c6fbb485112
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/34c2a1e6b2373afcf0e11e7a1387aced82669b9d
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/dd2cd9fec90267ed9b34e93a46a26b36fbbb457f
CVE-2026-40019 (An unauthenticated attacker can send a truncated quoted argument to th ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40019-v2-4-3-regression-managesieve-login-pre-auth-infinite-loop
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1caacffe4e94382eda606e29f90a16b6761f6d6a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1caacffe4e94382eda606e29f90a16b6761f6d6a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/18d1b11a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list