-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 03 Apr 2026 13:58:21 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-lucene dovecot-lucene-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: i386 Version: 1:2.3.19.1+dfsg1-2.1+deb12u2 Distribution: bookworm-security Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-lucene - secure POP3/IMAP server - Lucene support dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Changes: dovecot (1:2.3.19.1+dfsg1-2.1+deb12u2) bookworm-security; urgency=medium . * [34fb460] import upstream fixes for several CVEs - CVE-2025-59031: Remove unsafe decode2text shell script - CVE-2025-59032: ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response - CVE-2026-0394: potential path traversal when configured to use per-domain passwd - CVE-2026-27855: OTP driver vulnerable to replay attack. - CVE-2026-27856: Doveadm credentials were not checked using timing-safe checking function - CVE-2026-27857: Sending excessive parenthesis causes imap-login to use excessive memory - CVE-2026-27858: managesieve-login can allocate large amount of memory during authentication - CVE-2026-27859: Excessive RFC 2231 MIME parameters in email would cause excessive CPU usage Checksums-Sha1: ec9fddfc3a7d411a1606c78dc3644693a69fa314 29564 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 3d4d431582b2253ab95226a8c1753d3d0cafaf4c 1368008 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 4366cd13c71309f259fc225d5de4f141ac0a1414 9521156 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 86ba26449af290427b38ef23188f7a1f24aa97de 4736192 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 3b5df79d687edac9a99a7cb3bc6c644bcc1d90e1 1743488 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb b81a8d4680a8bcaccb9923c4c4d8901c195b6bd3 19920 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 589848872a5ca073c95989424a556451ea2190e6 1363428 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb eefda089046530606c1492fc216393654eababf5 669032 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb b4a79b075fc1d66c918e4a61ea35001f86b5dcde 1550032 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 302e1fa2054b1b7e9a839bc047e2c40da41f6d0b 112056 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 3ede4e5489254200a9e6f7aa64c2fb39fa05ed6b 1397420 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 161d4fc781e5cfd24fb0afa619f502de6f13981d 86032 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 76b1a3235a23719a0ab737a5944c1fa9882a8d2a 1380140 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 24569f324418e0876ae8a9fd65cdf0d2c1456bd9 146776 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 78348740de38a4947ae09a8f67815701f73eec39 1384996 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 8a9b21c2d1b0a9a16237725becb9fd352a1883be 149848 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 7f7213bbebdbcb5eae16f80d152c0ffb55daeed5 1403172 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 4a5525e6bf5e434c2fc251b3cb31950e84ee6967 29680 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb cdccbbcaffb433dc6e55dc365b788644478f22ca 1365516 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb ca7e15cd0870c6de51417fa3c7ba8f890de2d344 29592 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb b8bd1197000571dc9ee5d504db31cf3b4d812f3a 1369508 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb fc0271eae956db80241d7d5d8dbf92121173787b 86164 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 3a09d58de71131b24236012acc00cf2c83be8771 1389192 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb af51a89e78b26ae4d1c50373d0879fd85dc35d29 1423932 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 2ddbcc1f43355474aa9aed7544370b8326f0c58e 1733608 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb b3fe4732b091b7581b5cdc07ae044ffaa72e2984 81128 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 4d1076363c7e16ab5c19dee316b64c1c91ce0bc8 1377872 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 1eec0606870a4e3a3923f6b45cba08461bcac22b 16176 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 7cef708e0387223270b07de3f5fceec1354dd0a3 1363200 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb abbb5db70a276707f1010b92ac86e81eb386d713 168256 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 2c9236600ef42b73faf2d78eda3af3a693617016 1406460 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb c1be3beb9a48f9ad570648cd99e08c50025b6507 18690 dovecot_2.3.19.1+dfsg1-2.1+deb12u2_i386-buildd.buildinfo Checksums-Sha256: b2d76d99694a9601f257f4226c5293ea49ef9c0adde5829d0938491849a12a40 29564 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 09777bcebf01a66e48a9d8653988a1d5e1c73dbea1a07ed592e0d434dfd0f951 1368008 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 5ce82d73a0e1916f81709be55d533c80d7227859738708803512111047f34225 9521156 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 3429469bf735ab6824618309156890d67d43859d3da78e88a7501bd4ad5483f0 4736192 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 4841d4a6de0ce7513420584cb39b5045899db208ed721c5dd90a1fd592164be3 1743488 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 3c9afd8245eb6303d77d6cce19507a6314cc87529645e421e19a54ed09a45935 19920 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 467b9349d19d73596cb62c605627221eadb5b1b77b2f46d474041ad8b93b514d 1363428 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb a439a5d9f6c1ec36c52bc1cb98ee839f7cad2397be7342581298891293e2d371 669032 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 480e550ec35d0f5e14b548b157b87a0a526f81f00467c5e223078a2cc90d95df 1550032 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 5d316056366b645603cbe16e1c278485034722f42f0c23129b5d1838303c55cd 112056 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 52220f79f40a35d30438db1075c28f421b52ec45198ce19c155aaa38391c9b02 1397420 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 3c53ffddabea30251ea888e3862c8b3266dbeafbf5df87d1c9b384b902555129 86032 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 9232be48e0d60870cdaa5a9b6955b3dbcc2e4561242798b7f2490380994f6776 1380140 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 178bc3620f9acc2786362056e217a8bd9ce8e8f792484f6917d4306b79069926 146776 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 7d988484dd97aa0c41e7be3d225f0c4413b1d25411d06bf0f30245b6b2c91b8d 1384996 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 7cd6a7108031aa4d2bee602ab12414ce991cfc053b74bb63efe482578001827b 149848 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 62195896a7aa8465d3b8402bd8f9b9691269b520c427dbd28e754926a4358ebc 1403172 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb d128d6000456960bff6e1bf471bfabc0c9784072fe440dfe919a0c66dbc07d6c 29680 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb b67938a588962f3fdfc0ff092b706a445fe60e2e5a2e97d8ff28171aab08e9fa 1365516 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 13dc260948f3e182c16c42fec55a2b1e020f6e09c1d5da66e02f6cdc16ea0ca1 29592 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb d381bdc046c4b2ec8c6d0336e23651e131843670eecc533ef2ef6de9c7ad3e9b 1369508 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 57add548771693dbf5b4a264782d319596879d4b2781b42190a395c1d5cdbaed 86164 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb d84123fd17ec6c5eb94982d28dab72938553dd3eed3b8f130f69139df655b33b 1389192 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb ffbd9a5d0d4317c0747aebc6edf66241c05e295849a526fdb859408fb005b885 1423932 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb aa07b15a6a55b4c51c667acf44eb06e77073aa68e982625c280d5a06cd0b89f1 1733608 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb ff4f91d84ce7c828cdf93d5697578fe4929c7d2b94f1a7a115336fd994d5a06f 81128 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 7f87b48608380b5cd75a9defcdfee52692df834f356425a01a37468ed61ffa85 1377872 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb fd511c95be712278ff2968da44abd9268ea85da39ca1d92434f9bc64312ea06d 16176 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb f21c0dd1dd680e12b89cf39536e2aae007cccf82c7dd05b8a1d4ef10a5f697e8 1363200 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb a05c608a13a570d3b99a633d31f76cebd2834a92d9933ab553bf8aee676e6762 168256 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 611ca4181a6fc48195b24505496285a3485dae245f23b1944b89ea81d7f21ca6 1406460 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 6e22f9bfa0a46e2e662f9aadf675ee9db2b5835eadab90cf4fb9d894db0b76a8 18690 dovecot_2.3.19.1+dfsg1-2.1+deb12u2_i386-buildd.buildinfo Files: 8abf30b5ab3d203c4c71b403b31b6a9f 29564 debug optional dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 7d59b86c90ba07a01bd05bf1b1869f13 1368008 mail optional dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 8ab063d6543ac42ee140ea89239ad3d5 9521156 debug optional dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 62da16391507ee46dd2e4b3f9c7b1d1c 4736192 mail optional dovecot-core_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb f260a49f737253317b7b1eaadc029b87 1743488 mail optional dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb f48bbfc8b18441fbf8dd0cd786166fd7 19920 debug optional dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 7347057c90259fe7610f7f4bbf51f1aa 1363428 mail optional dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 0b48e44e2eba231043b6eacd84586bb2 669032 debug optional dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb ee31a6016d01b90c4a5339ad0d642514 1550032 mail optional dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 6a9afad9280f073bfa0dbe404c64ea7d 112056 debug optional dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 4d5a5fc825b1e222bd33b2468173e6bf 1397420 mail optional dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 409b22a5a7ae3cdee46acbf9198bccdd 86032 debug optional dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb dd296ee55d84da5723eceb5cc9d1ad9e 1380140 mail optional dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb aba3d9287977e856a1fee540844a681e 146776 debug optional dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 2f95c4dad60406ea910fe3c6c06643a1 1384996 mail optional dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 886d587410bd45b98ed8777da856f62e 149848 debug optional dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 032d67a81707d092c57edda1bc2e796f 1403172 mail optional dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 402f86bb464ba5b4632a0ede0b879962 29680 debug optional dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 6fd404ff397536e35147657d8d50dd69 1365516 mail optional dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 64d577d94624a38008563f2435acef4e 29592 debug optional dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 386154602af8b7dd2b7a104faeb61677 1369508 mail optional dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 155495053f674a42434ff9016220571b 86164 debug optional dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 5420e1b8f06c2c57953897d8951c312e 1389192 mail optional dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb dfc1fcfcb2d20152209121be90a718dc 1423932 debug optional dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 9a5ed0cbc5141b0cd4e75c64c108865f 1733608 mail optional dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 4b23daec600afd7ab317a7ebff018714 81128 debug optional dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb db7fa546b5ae1bfb13c4c5ebd06fa64f 1377872 mail optional dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb ec78325aa25407f1d9b65e2ade5e7bf0 16176 debug optional dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 8c1deee8182676ec9f961160f7f59e86 1363200 mail optional dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 0da092533bf1b37fc2eddb91f02473c3 168256 debug optional dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb ecac10b4b8c94adea32d73ea34d97421 1406460 mail optional dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u2_i386.deb 73254e8170dbc28160fcbfd18ec66b3d 18690 mail optional dovecot_2.3.19.1+dfsg1-2.1+deb12u2_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmnQOiMACgkQf2INRiCd aWJ+AxAAnT3qWKHVI28/1z6oosg6IVn7Zz0nfI3FrjSoJpFzrP6cNP00NsljrD5X uKdceairRc+T5rpgX/dba/cEfSSffTWVbpwjYbWIzSptVZkt4qXuMQ0XXIkl7H2b Ua6KrEPmc0emfG9TSHZZ7YhumynZiG6nFmxFdzRbtweD0l+r45ayYOLEyOCSUHr2 tiwFO9ncM6bKnRMVNs+R3m7y+4JUdqNzonBzqbKwqyWDpRs0GdSKMpznD+Mzyk7v YI5lY7/3t2ecOh+4+qPASXfVL869KL/OLwZHy8ziU7GKcEZzZwGATgpBkqrMcBoM huOI4FoKu+FklScBwtfqHSJjetJBXHi++yu/Le2lbb8BseKMFLlc4mwpoI5dLUi7 sPsjZAHSJD+uiC7iBzc4K0tKfGaYutSL4+2r6RJ8s6/NnK6V+dbJqZN3iRy+5jN0 RH1I3TWrAbiEgCEST5dkeq+ALrrX6HfGqoKssgN+V6/Z/oN0A/aFosc9iKC/sb84 60ZWRvj5MDSZj5YFzQiPOp1YTQDAPDUKiv0z6eGxclip0ORCLxztAuIQd3fh6w8+ 6ArqMztKf5FPC2+TAyQNR1LEuEc2Y7RHiH3IFSHkf2kcvSg8pYJMyQZ8KGKjwZB/ nCOjyvIDnV+xY6AlLp+ektCUTyCk0LXiX0LxGTiOQr70jJzGo0I= =wZB2 -----END PGP SIGNATURE-----