Your message dated Wed, 05 Oct 2005 04:32:09 -0700
with message-id <[EMAIL PROTECTED]>
and subject line Bug#312245: fixed in mailutils 1:0.6.1-4sarge2
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 6 Jun 2005 16:32:48 +0000
>From [EMAIL PROTECTED] Mon Jun 06 09:32:48 2005
Return-path: <[EMAIL PROTECTED]>
Received: from (futura.tixteam.net) [213.174.176.29] 
        by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
        id 1DfKWu-0006Uu-00; Mon, 06 Jun 2005 09:32:48 -0700
Received: from localhost (localhost [127.0.0.1])
        by futura.tixteam.net (Postfix) with ESMTP id 86D2DB0D77
        for <[EMAIL PROTECTED]>; Mon,  6 Jun 2005 18:32:46 +0200 (CEST)
Received: from futura.tixteam.net ([127.0.0.1])
        by localhost (futura [127.0.0.1]) (amavisd-new, port 10024) with LMTP
        id 03271-02 for <[EMAIL PROTECTED]>;
        Mon, 6 Jun 2005 18:32:46 +0200 (CEST)
Received: from tie (unknown [128.54.210.194])
        by futura.tixteam.net (Postfix) with ESMTP id 43783B0D75
        for <[EMAIL PROTECTED]>; Mon,  6 Jun 2005 18:32:44 +0200 (CEST)
Received: by tie (sSMTP sendmail emulation); Mon,  6 Jun 2005 09:32:56 -0700
Received: by tie (hashcash-sendmail, from uid 1000);
        Mon, 6 Jun 2005 09:32:56 -0700
Date: Mon, 6 Jun 2005 09:32:55 -0700
From: Guido Trotter <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: mailutils: The security fix breaks mailbox compatibility
Message-ID: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Reportbug-Version: 3.8
X-Debbugs-Cc: [EMAIL PROTECTED]
User-Agent: Mutt/1.5.9i
X-Hashcash: 1:20:050606:[EMAIL PROTECTED]::sm9kYnA9T/AI6JyO:000000000000000
        0000000000000000000000005QRi
X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at quaqua.net
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-11.0 required=4.0 tests=BAYES_00,HAS_PACKAGE,
        X_DEBBUGS_CC autolearn=ham version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Package: mailutils
Version: 0.6.1-4
Severity: important

Hi!

I upgraded a server featuring mailutils form version 0.6.1-1 to version
0.6.1-4. After the upgrade the users weren't able to read mail in some
mailboxes anymore. 

In particular the server answers:
UID SEARCH Bogus number set (near end) 
to
SEARCH UID 1:9

or 

UID FETCH Bogus message set: message number out of range
to
FETCH 1:* (FLAGS UID RFC822.SIZE BODY.PEEK[HEADER.FIELDS (Date To Cc From 
Subject X-Priority Content-Type)])

and so accessing those mailboxes is impossible. (The interface used is
squirrelmail, configured to access a mailserver of type "other". The
same configuration with 0.6.1-1 works).

Guido

---------------------------------------
Received: (at 312245-close) by bugs.debian.org; 5 Oct 2005 11:39:09 +0000
>From [EMAIL PROTECTED] Wed Oct 05 04:39:09 2005
Return-path: <[EMAIL PROTECTED]>
Received: from katie by spohr.debian.org with local (Exim 3.36 1 (Debian))
        id 1EN7VJ-0002V0-00; Wed, 05 Oct 2005 04:32:09 -0700
From: Jordi Mallach <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
X-Katie: $Revision: 1.56 $
Subject: Bug#312245: fixed in mailutils 1:0.6.1-4sarge2
Message-Id: <[EMAIL PROTECTED]>
Sender: Archive Administrator <[EMAIL PROTECTED]>
Date: Wed, 05 Oct 2005 04:32:09 -0700
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
        autolearn=no version=2.60-bugs.debian.org_2005_01_02

Source: mailutils
Source-Version: 1:0.6.1-4sarge2

We believe that the bug you reported is fixed in the latest version of
mailutils, which is due to be installed in the Debian FTP archive:

libmailutils0-dev_0.6.1-4sarge2_i386.deb
  to pool/main/m/mailutils/libmailutils0-dev_0.6.1-4sarge2_i386.deb
libmailutils0_0.6.1-4sarge2_i386.deb
  to pool/main/m/mailutils/libmailutils0_0.6.1-4sarge2_i386.deb
mailutils-comsatd_0.6.1-4sarge2_i386.deb
  to pool/main/m/mailutils/mailutils-comsatd_0.6.1-4sarge2_i386.deb
mailutils-doc_0.6.1-4sarge2_all.deb
  to pool/main/m/mailutils/mailutils-doc_0.6.1-4sarge2_all.deb
mailutils-imap4d_0.6.1-4sarge2_i386.deb
  to pool/main/m/mailutils/mailutils-imap4d_0.6.1-4sarge2_i386.deb
mailutils-mh_0.6.1-4sarge2_i386.deb
  to pool/main/m/mailutils/mailutils-mh_0.6.1-4sarge2_i386.deb
mailutils-pop3d_0.6.1-4sarge2_i386.deb
  to pool/main/m/mailutils/mailutils-pop3d_0.6.1-4sarge2_i386.deb
mailutils_0.6.1-4sarge2.diff.gz
  to pool/main/m/mailutils/mailutils_0.6.1-4sarge2.diff.gz
mailutils_0.6.1-4sarge2.dsc
  to pool/main/m/mailutils/mailutils_0.6.1-4sarge2.dsc
mailutils_0.6.1-4sarge2_i386.deb
  to pool/main/m/mailutils/mailutils_0.6.1-4sarge2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jordi Mallach <[EMAIL PROTECTED]> (supplier of updated mailutils package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Wed, 14 Sep 2005 11:21:14 +0200
Source: mailutils
Binary: mailutils-mh mailutils-imap4d mailutils-comsatd mailutils 
libmailutils0-dev libmailutils0 mailutils-pop3d mailutils-doc
Architecture: source i386 all
Version: 1:0.6.1-4sarge2
Distribution: stable
Urgency: high
Maintainer: Jordi Mallach <[EMAIL PROTECTED]>
Changed-By: Jordi Mallach <[EMAIL PROTECTED]>
Description: 
 libmailutils0 - GNU Mail abstraction library
 libmailutils0-dev - Development files for GNU mailutils
 mailutils  - GNU mailutils utilities for handling mail
 mailutils-comsatd - GNU mailutils-based comsatd daemon
 mailutils-doc - Documentation for GNU mailutils
 mailutils-imap4d - GNU mailutils-based IMAP4 Daemon
 mailutils-mh - GNU mailutils-based MH utilities
 mailutils-pop3d - GNU mailutils-based POP3 Daemon
Closes: 312245 317842
Changes: 
 mailutils (1:0.6.1-4sarge2) stable; urgency=high
 .
   * debian/patches/05_imap4d_bad_uid.patch: modified patch from
     Bas Wijnen to fix the behaviour of imap4d when fetching non-existing
     UIDs, introduced in -3 (closes: #317842, #312245).
   * Move security patch of -4sarge1 to debian/patches/06_CAN-2005-2878.
Files: 
 08f194638ced87d1a008225be9c53acc 1105 libs optional mailutils_0.6.1-4sarge2.dsc
 780a90fe9865b48e139cd329be8d8dd2 37565 libs optional 
mailutils_0.6.1-4sarge2.diff.gz
 406a18a464b31fd6f3f85875c8a1d5be 287422 doc optional 
mailutils-doc_0.6.1-4sarge2_all.deb
 ef487061bc3c299fed03da67335ebd67 546794 libs optional 
libmailutils0_0.6.1-4sarge2_i386.deb
 1f3abe59a2cd11f71672825876e8e294 368224 libdevel optional 
libmailutils0-dev_0.6.1-4sarge2_i386.deb
 4c4e2d5a254f2c45f60fb7607e50082d 143716 mail optional 
mailutils_0.6.1-4sarge2_i386.deb
 c99d6575b5c2dab592193b2e6edd67e8 75124 net optional 
mailutils-imap4d_0.6.1-4sarge2_i386.deb
 322d16884ab02c4928276cb711942ddb 60556 net optional 
mailutils-pop3d_0.6.1-4sarge2_i386.deb
 de1c810761412d0e856129d56499bf36 46704 net optional 
mailutils-comsatd_0.6.1-4sarge2_i386.deb
 957f85abb2c66d22eceae094b721792d 648498 mail optional 
mailutils-mh_0.6.1-4sarge2_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDQ7dDJYSUupF6Il4RAtMPAJwIWQR73dcCEmHJwAe4yCBSJ2/fbwCgxY9M
N7nszmWRtyjApHAKW6M7AhE=
=5gmx
-----END PGP SIGNATURE-----


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to