Bug#1016351: dovecot: CVE-2022-30550

2022-07-30 Thread Moritz Mühlenhoff
Am Fri, Jul 29, 2022 at 02:52:32PM -0700 schrieb Noah Meyerhans: > My inclination is that this won't need a DSA and can wait for a bullseye > point release, Agreed! Marking it as such in the Debian Security Tracker. Cheers, Moritz

Processed: Re: Bug#1016351: dovecot: CVE-2022-30550

2022-07-29 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + pending Bug #1016351 [src:dovecot] dovecot: CVE-2022-30550 Added tag(s) pending. -- 1016351: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1016351 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1016351: dovecot: CVE-2022-30550

2022-07-29 Thread Noah Meyerhans
Control: tags -1 + pending The fix targeting sid is pending review on salsa. My inclination is that this won't need a DSA and can wait for a bullseye point release, but I'm open to other opinions. -- Sent from my Android device with K-9 Mail. Please excuse my brevity.

Bug#1016351: dovecot: CVE-2022-30550

2022-07-29 Thread Moritz Mühlenhoff
Source: dovecot X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for dovecot. CVE-2022-30550[0]: | An issue was discovered in the auth component in Dovecot 2.2 and 2.3 | before 2.3.20. When two passdb configuration entries exist