[Bug 2077324] Re: [FFE] CVE-2024-23184/CVE-2024-23185

2024-10-07 Thread Mitchell Dzurick
Focal,Jammy uploaded separately. Just marking as fix released. ** Changed in: dovecot (Ubuntu Jammy) Status: Triaged => Fix Committed ** Changed in: dovecot (Ubuntu Focal) Status: Triaged => Fix Released ** Changed in: dovecot (Ubuntu Jammy) Status: Fix Committed => Fix Rele

[Bug 2077324] Re: [FFE] CVE-2024-23184/CVE-2024-23185

2024-09-01 Thread Launchpad Bug Tracker
This bug was fixed in the package dovecot - 1:2.3.21+dfsg1-2ubuntu6 --- dovecot (1:2.3.21+dfsg1-2ubuntu6) noble-security; urgency=medium * Patches for CVE-2024-23184, CVE-2024-23185 (LP: #2077324). - CVE-2024-23184: A large number of address headers in email resulted in ex

[Bug 2077324] Re: [FFE] CVE-2024-23184/CVE-2024-23185

2024-08-29 Thread Utkarsh Gupta
** No longer affects: dovecot (Ubuntu Bionic) ** Changed in: dovecot (Ubuntu Focal) Status: New => Triaged ** Changed in: dovecot (Ubuntu Jammy) Status: New => Triaged ** Changed in: dovecot (Ubuntu Noble) Status: New => Triaged -- You received this bug notification becaus

[Bug 2077324] Re: [FFE] CVE-2024-23184/CVE-2024-23185

2024-08-27 Thread Launchpad Bug Tracker
This bug was fixed in the package dovecot - 1:2.3.21.1+dfsg1-1ubuntu1 --- dovecot (1:2.3.21.1+dfsg1-1ubuntu1) oracular; urgency=medium * Merge with Debian unstable (LP: #2077324). Remaining changes: - d/rules: set mbranch-protection=bti to avoid ftbfs. -- Mitchell Dzurick Fr

[Bug 2077324] Re: [FFE] CVE-2024-23184/CVE-2024-23185

2024-08-27 Thread Graham Inggs
FFe granted, please go ahead ** Changed in: dovecot (Ubuntu Oracular) Status: In Progress => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2077324 Title: [FFE] CVE-2024-23184/CVE-20

[Bug 2077324] Re: [FFE] CVE-2024-23184/CVE-2024-23185

2024-08-27 Thread Mitchell Dzurick
** Description changed: - There is a new minor/security patch for Dovecot, to mitigate the two DoS - vulnerabilities. The fix should be merged into the supported Ubuntu - version packages. + [ Impact ] + + - CVE-2024-23184: A large number of address headers in email resulted + in excessive CPU

[Bug 2077324] Re: [FFE] CVE-2024-23184/CVE-2024-23185

2024-08-27 Thread Mitchell Dzurick
** Summary changed: - 2.3.21.1 released mitigating CVE-2024-23184/CVE-2024-23185 + [FFE] CVE-2024-23184/CVE-2024-23185 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2077324 Title: [FFE] CVE-2024-23