[Buildroot] [PATCH] package/dovecot: add upstream security fix for CVE-2022-30550

Peter Korsgaard peter at korsgaard.com
Wed Dec 7 07:10:46 UTC 2022


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before
 > 2.3.20.  When two passdb configuration entries exist with the same driver
 > and args settings, incorrect username_filter and mechanism settings can be
 > applied to passdb definitions.  These incorrectly applied settings can lead
 > to an unintended security configuration and can permit privilege escalation
 > in certain configurations.  The documentation does not advise against the
 > use of passdb definitions that have the same driver and args settings.  One
 > such configuration would be where an administrator wishes to use the same
 > PAM configuration or passwd file for both normal and master users but use
 > the username_filter setting to restrict which of the users is able to be a
 > master user.

 > https://dovecot.org/pipermail/dovecot-news/2022-July/000477.html

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2022.08.x and 2022.02.x, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list