security advisorydebianinformation security
A flaw with the authentication cache management was discovered in the Dovecot email server, which could result in users being logged in as the wrong user in certain configurations. For the stable distribution (trixie), this problem has been fixed in version 1:2.4.1+dfsg1-6+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6019-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso October 05, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : dovecot Debian Bug : 1115474 1115964 A flaw with the authentication cache management was discovered in the Dovecot email server, which could result in users being logged in as the wrong user in certain configurations. For the stable distribution (trixie), this problem has been fixed in version 1:2.4.1+dfsg1-6+deb13u1. We recommend that you upgrade your dovecot packages. For the detailed security status of dovecot please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/dovecot Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical flaw in Dovecot's authentication cache could log users as incorrect accounts. Update recommended for stability.. Dovecot security flaw, Debian notification, user login issue, authentication fix. . Severity: Critical. LinuxSecurity.com Team
Oct 05, 2025
•Critical
Debian