[ubuntu/questing-proposed] dovecot 1:2.4.1+dfsg1-5ubuntu4 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Tue Oct 7 14:20:43 UTC 2025


dovecot (1:2.4.1+dfsg1-5ubuntu4) questing; urgency=medium

  * SECURITY UPDATE: authentication cache bypass (LP: #2126984)
    - debian/patches/CVE-2025-30189.patch: use AUTH_CACHE_KEY_USER instead
      of per-database constants in src/auth/auth-settings.h,
      src/auth/passdb-bsdauth.c, src/auth/passdb-oauth2.c,
      src/auth/passdb-pam.c, src/auth/passdb-passwd.c,
      src/auth/userdb-passwd.c.
    - CVE-2025-30189

Date: Tue, 07 Oct 2025 07:17:56 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/dovecot/1:2.4.1+dfsg1-5ubuntu4
-------------- next part --------------
Format: 1.8
Date: Tue, 07 Oct 2025 07:17:56 -0400
Source: dovecot
Built-For-Profiles: noudeb
Architecture: source
Version: 1:2.4.1+dfsg1-5ubuntu4
Distribution: questing
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Launchpad-Bugs-Fixed: 2126984
Changes:
 dovecot (1:2.4.1+dfsg1-5ubuntu4) questing; urgency=medium
 .
   * SECURITY UPDATE: authentication cache bypass (LP: #2126984)
     - debian/patches/CVE-2025-30189.patch: use AUTH_CACHE_KEY_USER instead
       of per-database constants in src/auth/auth-settings.h,
       src/auth/passdb-bsdauth.c, src/auth/passdb-oauth2.c,
       src/auth/passdb-pam.c, src/auth/passdb-passwd.c,
       src/auth/userdb-passwd.c.
     - CVE-2025-30189
Checksums-Sha1:
 993969829bc7500fb6600ef7c217cb3f9eebf52c 3907 dovecot_2.4.1+dfsg1-5ubuntu4.dsc
 eca4b5ae907cce245f7086f4a634d4b71782ba76 87376 dovecot_2.4.1+dfsg1-5ubuntu4.debian.tar.xz
 574c888d1a04e9dd59c9e361e16662341f7f9aca 9075 dovecot_2.4.1+dfsg1-5ubuntu4_source.buildinfo
Checksums-Sha256:
 ced32131a6348f846afc452e5f5ac9350a9af661a879679b2108450c88857ac7 3907 dovecot_2.4.1+dfsg1-5ubuntu4.dsc
 9c78b38c082f90c461d888ac088bef33c9fa9600b9e608e2afaee29129b1d340 87376 dovecot_2.4.1+dfsg1-5ubuntu4.debian.tar.xz
 daec9c81f875eeb092c7733e5c520edfa99ef748784a99447f97acfd735ddb33 9075 dovecot_2.4.1+dfsg1-5ubuntu4_source.buildinfo
Files:
 f5ab790e0a2d1d64b3223bdc8ca14e52 3907 mail optional dovecot_2.4.1+dfsg1-5ubuntu4.dsc
 24d4114606bd4ffc75f6c78bc8144e41 87376 mail optional dovecot_2.4.1+dfsg1-5ubuntu4.debian.tar.xz
 1e852080d87a137ac1e6ae9b97b83fd1 9075 mail optional dovecot_2.4.1+dfsg1-5ubuntu4_source.buildinfo
Original-Maintainer: Dovecot Maintainers <dovecot at packages.debian.org>


More information about the Questing-changes mailing list