Re: Security advisory: uw-imap - 3 attachments

2005-10-14 Thread Eric Blake
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 According to Christian Weinberger on 10/14/2005 12:26 AM: I could not post to the cygwin applications list via gmane, so I reply to the main list. Apologies if this not the way it should be done. I don't know why cygwin-apps is registered as a

Re: Security advisory: uw-imap - 3 attachments

2005-10-14 Thread Christopher Faylor
On Fri, Oct 14, 2005 at 07:34:41AM -0600, Eric Blake wrote: According to Christian Weinberger on 10/14/2005 12:26 AM: I could not post to the cygwin applications list via gmane, so I reply to the main list. Apologies if this not the way it should be done. I don't know why cygwin-apps is

Re: Security advisory: uw-imap - 3 attachments

2005-10-14 Thread Eric Blake
cygwin-apps is a... wait for it... mailing list. It is a *moderated* mailing list. It is moderated for a reason. Having it moderated for email and not moderated for anyone who figured out how to use gmane has already been shown to be a bad idea. I don't want a back door method for

Re: Security advisory: uw-imap - 3 attachments

2005-10-14 Thread Christopher Faylor
On Fri, Oct 14, 2005 at 03:32:44PM +, Eric Blake wrote: cgf wrote: cygwin-apps is a... wait for it... mailing list. It is a *moderated* mailing list. It is moderated for a reason. Having it moderated for email and not moderated for anyone who figured out how to use gmane has already been

Re: Security advisory: uw-imap - 3 attachments

2005-10-14 Thread Christian Weinberger
uw-imap (whose maintainer, AFAICS, has yet to respond to reply to Corinna's message) is vulnerable to remote overflow of a buffer in the IMAP server leading to execution of arbitrary code. The only solution is to upgrade to 2004g (current Cygwin release is 2002e!). I built 2004g and it

Re: Security advisory: uw-imap - 3 attachments

2005-10-14 Thread Eric Blake
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 According to Christian Weinberger on 10/14/2005 12:26 AM: I could not post to the cygwin applications list via gmane, so I reply to the main list. Apologies if this not the way it should be done. I don't know why cygwin-apps is registered as a