Skip to content
  1. Dec 05, 2022
  2. Dec 04, 2022
  3. Dec 03, 2022
  4. Dec 02, 2022
  5. Dec 01, 2022
  6. Nov 30, 2022
    • Peter Korsgaard's avatar
      package/dovecot: add upstream security fix for CVE-2022-30550 · 43899226
      Peter Korsgaard authored
      An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before
      2.3.20.  When two passdb configuration entries exist with the same driver
      and args settings, incorrect username_filter and mechanism settings can be
      applied to passdb definitions.  These incorrectly applied settings can lead
      to an unintended security configuration and can permit privilege escalation
      in certain configurations.  The documentation does not advise against the
      use of passdb definitions that have the same driver and args settings.  One
      such configuration would be where an administrator wishes to use the same
      PAM configuration or passwd file for both normal and master users but use
      the username_filter setting to restrict which of the users is able to be a
      master user.
      
      https://dovecot.org/pipermail/dovecot-news/2022-July/000477.html
      
      
      
      Signed-off-by: default avatarPeter Korsgaard <peter@korsgaard.com>
      43899226
  7. Nov 29, 2022
  8. Nov 25, 2022
Loading