Package: dovecot
Version: 1.0.rc15-2etch4
Severity: normal

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for dovecot.

CVE-2009-3235[0]:
| Multiple stack-based buffer overflows in the Sieve plugin in Dovecot
| 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve,
| allow context-dependent attackers to cause a denial of service (crash)
| and possibly execute arbitrary code via a crafted SIEVE script, as
| demonstrated by forwarding an e-mail message to a large number of
| recipients, a different vulnerability than CVE-2009-2632.


These are already fixed in debian unstable.
Please coordinate with the security team ([email protected]) to
prepare packages for the stable and oldstable releases.


If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3235
    http://security-tracker.debian.net/tracker/CVE-2009-3235
    Patch: http://hg.dovecot.org/dovecot-sieve-1.1/rev/049f22520628
           http://hg.dovecot.org/dovecot-sieve-1.1/rev/4577c4e1130d

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkq3uhYACgkQNxpp46476arb+wCfWrHakSEdLqISPuacuz8HjMKj
nPkAnRz25JCJzXjK/WOMIlpSrwf+Sdnj
=6BRf
-----END PGP SIGNATURE-----



-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to