Debian alert DLA-4617-1 (dovecot)
| From: | Guilhem Moulin <guilhem@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4617-1] dovecot security update | |
| Date: | Fri, 05 Jun 2026 14:28:03 +0200 | |
| Message-ID: | <aiLA04ZNPYAwnU2F@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4617-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin June 05, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : dovecot Version : 1:2.3.13+dfsg1-2+deb11u4 CVE ID : CVE-2026-33603 CVE-2026-40020 CVE-2026-42006 Debian Bug : 1136444 Multiple vulnerabilities were discovered in dovecot, a POP3/IMAP server, which could lead to Denial of Service or information leak. CVE-2026-33603 An attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding and later eavesdrop communications between Dovecot and client as MITM proxy. CVE-2026-40020 An attacker can use the IMAP `SETACL` command to inject the anyone permission to user's dovecot-acl file even if `imap_acl_allow_anyone=no`, thereby allowing folders to be spammed to all users. (The impact was limited to being able to spam folders to other users. No unexpected access is gained.) CVE-2026-42006 An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. This stems from an incomplete fix for CVE-2026-27857. For Debian 11 bullseye, these problems have been fixed in version 1:2.3.13+dfsg1-2+deb11u4. We recommend that you upgrade your dovecot packages. For the detailed security status of dovecot please refer to its security tracker page at: https://security-tracker.debian.org/tracker/dovecot Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmoiwNEACgkQ05pJnDwh pVJhPQ//VZgQsnFZM95N7NAdeojKKMH4jnWlc9eKictkIFu+HckZ+HMNkR5Ko1nl 2l4nTiukRnqTSGbjkbSUwtj/8ncZQtyWN728gCOmOfUiojok0blWO90wSi7AMivC A6day8cYHmcKh7Je1KJjPom/Ap/MoIWbOrtCo/5JpPImYqwJMEjPn9q7CDPkTQQ/ 89AoZIp087lIHV5gkwseiD48hm3GDx+mNJw7o57oO+Naf8t0sJ9SPKI6UVV6acUY +jbBtbmErGjD7lPjmHFJHrCrqRTRQ6+LI2O1h3fu2t1hJKDBBVl8vjf44+VAs9cu utg2aBtM07eT8cCjDccBcCGSGX96tEcFPSD8yE0TGUHgEcybRYoq1+/LWO8vj3fJ K83XftdGW6CI5oNuG7FGeiE+Bdp0mosmCUpH/qjrKOWfHHIol0eKZ+XcH60SYk3y wMyL9QFwrz/XvKFfPO/UPoOebnpexF7WxlvF6Ool4nZ5oP0WipKlT2ovSF36Zpjq nI0zdQkkJPCf1wIKv8G/0lodkuOnTajHbzNovCVmTjhFqYE612t7GU1yzuAGGgUA WfVVz502/dRodUSMO5K1pA3RBPQbc6WqUNjJ3ek6RufSRt2AuKL7J6kPB2+3IIEs x4NDCfJRkzNA82VeM53BqU90S3vePS3fI341BxSvf9Ys7NLi5yY= =nwe4 -----END PGP SIGNATURE-----
