[Buildroot] [PATCH] package/dovecot: add upstream security fix for CVE-2022-30550
Peter Korsgaard
peter at korsgaard.com
Wed Dec 7 07:10:46 UTC 2022
>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:
> An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before
> 2.3.20. When two passdb configuration entries exist with the same driver
> and args settings, incorrect username_filter and mechanism settings can be
> applied to passdb definitions. These incorrectly applied settings can lead
> to an unintended security configuration and can permit privilege escalation
> in certain configurations. The documentation does not advise against the
> use of passdb definitions that have the same driver and args settings. One
> such configuration would be where an administrator wishes to use the same
> PAM configuration or passwd file for both normal and master users but use
> the username_filter setting to restrict which of the users is able to be a
> master user.
> https://dovecot.org/pipermail/dovecot-news/2022-July/000477.html
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
Committed to 2022.08.x and 2022.02.x, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list