UbuntuUpdates.org

Bugs fixes in "dovecot"

Origin Bug number Title Date fixed
CVE CVE-2026-27855 Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, the 2026-03-31
CVE CVE-2026-0394 When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowe 2026-03-31
CVE CVE-2025-59032 ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, makin 2026-03-31
CVE CVE-2025-59031 Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use speciall 2026-03-31
Launchpad 2142200 dovecot-core: OAuth2 JWT validation fails with client_id set but aud is missing when aud claim is an array 2026-03-11
Launchpad 2142200 dovecot-core: OAuth2 JWT validation fails with client_id set but aud is missing when aud claim is an array 2026-03-11
Launchpad 2142200 dovecot-core: OAuth2 JWT validation fails with client_id set but aud is missing when aud claim is an array 2026-03-02
Launchpad 2142200 dovecot-core: OAuth2 JWT validation fails with client_id set but aud is missing when aud claim is an array 2026-03-02
CVE CVE-2024-23185 Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. Howe 2024-09-16
CVE CVE-2024-23184 Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 2024-09-16
CVE CVE-2024-23185 Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. Howe 2024-09-16
CVE CVE-2024-23184 Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 2024-09-16
CVE CVE-2024-23185 Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. Howe 2024-09-16
CVE CVE-2024-23184 Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 2024-09-16
CVE CVE-2024-23185 Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. Howe 2024-09-16
CVE CVE-2024-23184 Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 2024-09-16
Launchpad 2077324 [FFE] CVE-2024-23184/CVE-2024-23185 2024-09-02
Launchpad 2077324 [FFE] CVE-2024-23184/CVE-2024-23185 2024-09-02
Launchpad 2077324 [FFE] CVE-2024-23184/CVE-2024-23185 2024-09-02
Launchpad 2077324 [FFE] CVE-2024-23184/CVE-2024-23185 2024-09-02



About   -   Send Feedback to @ubuntu_updates