{"id":"MGASA-2022-0296","summary":"Updated dovecot packages fix security vulnerability","details":"An issue was discovered in the auth component in Dovecot 2.2 and 2.3\nbefore 2.3.20. When two passdb configuration entries exist with the same\ndriver and args settings, incorrect username_filter and mechanism settings\ncan be applied to passdb definitions. These incorrectly applied settings\ncan lead to an unintended security configuration and can permit privilege\nescalation in certain configurations. The documentation does not advise\nagainst the use of passdb definitions that have the same driver and args\nsettings. One such configuration would be where an administrator wishes to\nuse the same PAM configuration or passwd file for both normal and master\nusers but use the username_filter setting to restrict which of the users\nis able to be a master user. (CVE-2022-30550)\n","modified":"2026-04-16T04:41:32.209321542Z","published":"2022-08-25T21:21:07Z","upstream":["CVE-2022-30550"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2022-0296.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=30618"},{"type":"WEB","url":"https://dovecot.org/pipermail/dovecot-news/2022-July/000477.html"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5509-1"},{"type":"WEB","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/532QM5GABOZURM72SXKWEPBBQKUHLQC3/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/OQ5EW32AQSRSHPFQZM5W3PEYEKPBKGNA/"}],"affected":[{"package":{"name":"dovecot","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/dovecot?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.17.1-1.2.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0296.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}