Bug#990566: dovecot: CVE-2021-33515 CVE-2021-29157 CVE-2020-28200

2021-07-20 Thread Salvatore Bonaccorso
Hi Noah, [sorry for lack of reply to the previous mail, busy with other stuff] On Tue, Jul 20, 2021 at 08:03:12AM -0700, Noah Meyerhans wrote: > On Mon, Jul 19, 2021 at 08:21:45AM -0700, Noah Meyerhans wrote: > > > > CVE-2021-33515[0]: > > > > | The submission service in Dovecot before 2.3.15

Bug#990566: dovecot: CVE-2021-33515 CVE-2021-29157 CVE-2020-28200

2021-07-20 Thread Noah Meyerhans
On Mon, Jul 19, 2021 at 08:21:45AM -0700, Noah Meyerhans wrote: > > > CVE-2021-33515[0]: > > > | The submission service in Dovecot before 2.3.15 allows STARTTLS > > > | command injection in lib-smtp. Sensitive information can be redirected > > > | to an attacker-controlled address. > > > > > >

Bug#990566: dovecot: CVE-2021-33515 CVE-2021-29157 CVE-2020-28200

2021-07-19 Thread Noah Meyerhans
On Sat, Jul 17, 2021 at 09:05:32PM +0200, Salvatore Bonaccorso wrote: > > CVE-2021-33515[0]: > > | The submission service in Dovecot before 2.3.15 allows STARTTLS > > | command injection in lib-smtp. Sensitive information can be redirected > > | to an attacker-controlled address. > > > >

Bug#990566: dovecot: CVE-2021-33515 CVE-2021-29157 CVE-2020-28200

2021-07-17 Thread Salvatore Bonaccorso
Hi Noah, On Fri, Jul 02, 2021 at 10:41:12AM +0200, Moritz Mühlenhoff wrote: > Source: dovecot > X-Debbugs-CC: t...@security.debian.org > Severity: grave > Tags: security > > Hi, > > The following vulnerabilities were published for dovecot. > > CVE-2021-33515[0]: > | The submission service in

Bug#990566: dovecot: CVE-2021-33515 CVE-2021-29157 CVE-2020-28200

2021-07-02 Thread Moritz Mühlenhoff
Source: dovecot X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for dovecot. CVE-2021-33515[0]: | The submission service in Dovecot before 2.3.15 allows STARTTLS | command injection in lib-smtp. Sensitive information can be