CVE-2022-30550

NameCVE-2022-30550
DescriptionAn issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3122-1
Debian Bugs1016351

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dovecot (PTS)jessie, jessie (lts)1:2.2.13-12~deb8u9fixed
stretch (security)1:2.2.27-3+deb9u7fixed
stretch (lts), stretch1:2.2.27-3+deb9u8fixed
buster, buster (lts)1:2.3.4.1-5+deb10u8fixed
buster (security)1:2.3.4.1-5+deb10u7fixed
bullseye1:2.3.13+dfsg1-2+deb11u1fixed
bullseye (security)1:2.3.13+dfsg1-2+deb11u2fixed
bookworm (security), bookworm1:2.3.19.1+dfsg1-2.1+deb12u1fixed
sid, trixie1:2.3.21.1+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dovecotsourcejessie(not affected)
dovecotsourcestretch(not affected)
dovecotsourcebuster1:2.3.4.1-5+deb10u7DLA-3122-1
dovecotsourcebullseye1:2.3.13+dfsg1-2+deb11u1
dovecotsource(unstable)1:2.3.19.1+dfsg1-21016351

Notes

https://www.openwall.com/lists/oss-security/2022/07/06/9
https://github.com/dovecot/core/commit/7bad6a24160e34bce8f10e73dbbf9e5fbbcd1904
https://github.com/dovecot/core/commit/a1022072e2ce36f853873d910287f466165b184b
[stretch] - dovecot <not-affected> (Vulnerable code introduced later)
[jessie] - dovecot <not-affected> (Vulnerable code introduced later)

Search for package or bug name: Reporting problems