CVE-2020-24386: IMAP hibernation allows accessing other peoples mail

Aki Tuomi aki.tuomi at open-xchange.com
Mon Jan 4 20:45:05 EET 2021


> On 04/01/2021 15:02 Dan Malm <dam at one.com> wrote:
> 
>  
> On 2021-01-04 13:03, Aki Tuomi wrote:
> > Vulnerable version: 2.2.26-2.3.11.3
> > Fixed version: 2.3.13
> 
> No fix for 2.2.36?
> 
> -- 
> BR/Mvh. Dan Malm, Systems Engineer, One.com

We have not made fix for 2.2.36 as it's EOLed. 

Aki


More information about the dovecot mailing list