Dovecot has issued advisories today (June 21): https://dovecot.org/pipermail/dovecot-news/2021-June/000460.html https://dovecot.org/pipermail/dovecot-news/2021-June/000461.html https://dovecot.org/pipermail/dovecot-news/2021-June/000462.html The first issue is fixed upstream in 2.3.15 and the other two are also fixed in 2.3.14.1: https://dovecot.org/pipermail/dovecot-news/2021-June/000459.html https://dovecot.org/pipermail/dovecot-news/2021-June/000457.html Mageia 7 and Mageia 8 are also affected.
Whiteboard: (none) => MGA8TOO, MGA7TOOStatus comment: (none) => Fixed upstream in 2.3.15
Ubuntu has issued an advisory for the last two issues today (June 21): https://ubuntu.com/security/notices/USN-4993-1
Assigning to Stig, who has done recent updates to this.
Assignee: bugsquad => smelror
openSUSE has issued an advisory for the last two issues today (June 25): https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VRGETVIUWL6C53ONKOWQB6XMHGC4U2YM/
CVE-2020-28200 is actually fixed in Pigeonhole 0.5.15: https://dovecot.org/pipermail/dovecot-news/2021-June/000458.html
Removing Mageia 7 from whiteboard due to EOL: https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/
Whiteboard: MGA8TOO, MGA7TOO => MGA8TOO
Fedora has issued an advisory for this today (July 5): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JB2VTJ3G2ILYWH5Y2FTY2PUHT2MD6VMI/
openSUSE has issued an advisory for the first two issues on August 31: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YLFYZS4WAYE6TU4PO3V2JUI7DPQEK73I/
CC: (none) => mageia
already fixed in cauldron. new version pushed in mga8: src: - dovecot-2.3.17.1-1.mga8
Version: Cauldron => 8Status comment: Fixed upstream in 2.3.15 => (none)CC: (none) => smelrorAssignee: smelror => qa-bugsWhiteboard: MGA8TOO => (none)
dovecot-pigeonhole-devel-2.3.17.1-1.mga8 dovecot-plugins-ldap-2.3.17.1-1.mga8 dovecot-plugins-pgsql-2.3.17.1-1.mga8 dovecot-plugins-mysql-2.3.17.1-1.mga8 dovecot-plugins-gssapi-2.3.17.1-1.mga8 dovecot-plugins-sqlite-2.3.17.1-1.mga8 dovecot-devel-2.3.17.1-1.mga8 dovecot-pigeonhole-2.3.17.1-1.mga8 dovecot-2.3.17.1-1.mga8
Installed but failed due to a missing dovecot.service file. The previously installed dovecot package had a service file. $ rpm -ql dovecot --root /media/btrfs/.snapshots/marte_root/2021-12-10_16\:58\:15_49___backup/ | grep service /usr/lib/systemd/system/dovecot.service $ rpm -ql dovecot | grep service
Confirmed problem as per comment 10. Adding feedback marker.
Keywords: (none) => feedbackCC: (none) => davidwhodgins
To downgrade to the working version use "urpmi --downgrade dovecot-2.3.13-1.mga8".
New build in progress. dovecot-2.3.17.1-1.1.mga8
dovecot-pigeonhole-devel-2.3.17.1-1.1.mga8 dovecot-plugins-ldap-2.3.17.1-1.1.mga8 dovecot-plugins-pgsql-2.3.17.1-1.1.mga8 dovecot-plugins-mysql-2.3.17.1-1.1.mga8 dovecot-plugins-sqlite-2.3.17.1-1.1.mga8 dovecot-plugins-gssapi-2.3.17.1-1.1.mga8 dovecot-devel-2.3.17.1-1.1.mga8 dovecot-pigeonhole-2.3.17.1-1.1.mga8 dovecot-2.3.17.1-1.1.mga8 from dovecot-2.3.17.1-1.1.mga8.src.rpm
Keywords: feedback => (none)
Tested with pop3s and imaps accounts within my lan. Validating the update.
Whiteboard: (none) => MGA8-64-OKKeywords: (none) => validated_updateCC: (none) => sysadmin-bugs
Keywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0557.html
Status: NEW => RESOLVEDResolution: (none) => FIXED