Opened 2 years ago
Closed 2 years ago
#17438 closed enhancement (fixed)
dovecot-2.3.20
Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
---|---|---|---|
Priority: | normal | Milestone: | 11.3 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New point version.
Change History (5)
comment:1 by , 2 years ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:2 by , 2 years ago
comment:3 by , 2 years ago
Both of the existing patches apply without issues, which is rather concerning. That means that upstream didn't fix CVE-2022-30550, and didn't make the OpenSSL3 fixes upstream
comment:4 by , 2 years ago
See: https://dovecot.org/pipermail/dovecot/2022-December/125885.html
According to the list:
On 23/12/2022 11:47 EET Eray Aslan <eraya at a21an.org> wrote:
On Thu, Dec 22, 2022 at 10:06:16AM +0200, Aki Tuomi wrote:
We are pleased to release v2.3.20 of Dovecot.
Can you confirm that CVE-2022-30550 is patched in dovecot-2.3.20? Thank you.
-- Eray
Hi!
We've decided to fix it for 2.4 release only, so it's not fixed in 2.3.20.
Aki
comment:5 by , 2 years ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
New:
Changes: