From: Markus Valentin Date: Thu, 23 Apr 2026 11:07:08 +0000 (+0200) Subject: [PATCH 2/2] auth: Fix prefixing forward_fields without a value from client X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~6 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=9c10ea7ba24a4ba102273abfe374fc267431d52c;p=dovecot.git [PATCH 2/2] auth: Fix prefixing forward_fields without a value from client Bare tokens (without '=') were not prefixed, only key=value pairs were. In practice this affected forward_fields, where a bare token such as 'nopassword' would land in extra_fields unprefixed instead of as 'forward_nopassword', allowing injection of internal auth control fields. Gbp-Pq: Name 0002-auth-Fix-prefixing-forward_fields-without-a-value-fr.patch --- diff --git a/src/auth/auth-fields.c b/src/auth/auth-fields.c index 8b92836..6e1ccbb 100644 --- a/src/auth/auth-fields.c +++ b/src/auth/auth-fields.c @@ -125,7 +125,7 @@ static void auth_fields_import_prefixed_args(struct auth_fields *fields, for (; *args != NULL; args++) { value = strchr(*args, '='); if (value == NULL) { - key = *args; + key = *prefix != '\0' ? t_strconcat(prefix, *args, NULL) : *args; } else { key = t_strdup_until(*args, value++); if (*prefix != '\0')