Re: [SOGo] ganz boesartiges how-to

2015-09-30 Thread mourik jan heupink

Hi Christian,

I think this is on purpose, it was (but a long time ago) also announced 
on this mailinglist.


MJ

On 29-9-2015 19:39, Christian Eichert wrote:

Nachdem man auf auf

http://www.sogo.nu/nc/support/faq/article/how-to-install-sogo-on-debian.html 



belehr wird die sogo keyring zu installieren wird man aufgefordert zu 
updaten
Die Sogo Repository  "updatet" dann unerwünschterweise pakete aus der 
standard debian repository

und bricht installationen

Holen: 1 http://inverse.ca/debian/ wheezy/wheezy dovecot-managesieved 
amd64 1:2.1.17-2~inverse11 [417 kB]
Holen: 2 http://inverse.ca/debian/ wheezy/wheezy dovecot-sieve amd64 
1:2.1.17-2~inverse11 [623 kB]
Holen: 3 http://inverse.ca/debian/ wheezy/wheezy dovecot-pop3d amd64 
1:2.1.17-2~inverse11 [388 kB]
Holen: 4 http://inverse.ca/debian/ wheezy/wheezy dovecot-pgsql amd64 
1:2.1.17-2~inverse11 [369 kB]
Holen: 5 http://inverse.ca/debian/ wheezy/wheezy dovecot-mysql amd64 
1:2.1.17-2~inverse11 [366 kB]
Holen: 6 http://inverse.ca/debian/ wheezy/wheezy dovecot-ldap amd64 
1:2.1.17-2~inverse11 [380 kB]
Holen: 7 http://inverse.ca/debian/ wheezy/wheezy dovecot-imapd amd64 
1:2.1.17-2~inverse11 [452 kB]
Holen: 8 http://inverse.ca/debian/ wheezy/wheezy dovecot-gssapi amd64 
1:2.1.17-2~inverse11 [365 kB]
Holen: 9 http://inverse.ca/debian/ wheezy/wheezy dovecot-core amd64 
1:2.1.17-2~inverse11 [3.028 kB]


Ich weiss nicht wie ich das einstufen soll.
Ist das ein Angriff ?



--
users@sogo.nu
https://inverse.ca/sogo/lists


Re: [SOGo] ganz boesartiges how-to

2015-09-30 Thread Sven Schwedas
No, this is not malware. But I'm curious why the SOGo repository
includes Dovecot builds, too. Just to compile them against newer library
versions, or are they patched in some way?

On 2015-09-29 19:39, Christian Eichert wrote:
> Nachdem man auf auf
> 
> http://www.sogo.nu/nc/support/faq/article/how-to-install-sogo-on-debian.html
> 
> 
> belehr wird die sogo keyring zu installieren wird man aufgefordert zu
> updaten
> Die Sogo Repository  "updatet" dann unerwünschterweise pakete aus der
> standard debian repository
> und bricht installationen
> 
> Holen: 1 http://inverse.ca/debian/ wheezy/wheezy dovecot-managesieved
> amd64 1:2.1.17-2~inverse11 [417 kB]
> Holen: 2 http://inverse.ca/debian/ wheezy/wheezy dovecot-sieve amd64
> 1:2.1.17-2~inverse11 [623 kB]
> Holen: 3 http://inverse.ca/debian/ wheezy/wheezy dovecot-pop3d amd64
> 1:2.1.17-2~inverse11 [388 kB]
> Holen: 4 http://inverse.ca/debian/ wheezy/wheezy dovecot-pgsql amd64
> 1:2.1.17-2~inverse11 [369 kB]
> Holen: 5 http://inverse.ca/debian/ wheezy/wheezy dovecot-mysql amd64
> 1:2.1.17-2~inverse11 [366 kB]
> Holen: 6 http://inverse.ca/debian/ wheezy/wheezy dovecot-ldap amd64
> 1:2.1.17-2~inverse11 [380 kB]
> Holen: 7 http://inverse.ca/debian/ wheezy/wheezy dovecot-imapd amd64
> 1:2.1.17-2~inverse11 [452 kB]
> Holen: 8 http://inverse.ca/debian/ wheezy/wheezy dovecot-gssapi amd64
> 1:2.1.17-2~inverse11 [365 kB]
> Holen: 9 http://inverse.ca/debian/ wheezy/wheezy dovecot-core amd64
> 1:2.1.17-2~inverse11 [3.028 kB]
> 
> Ich weiss nicht wie ich das einstufen soll.
> Ist das ein Angriff ?
> 

-- 
Mit freundlichen Grüßen, / Best Regards,
Sven Schwedas
Systemadministrator
TAO Beratungs- und Management GmbH | Lendplatz 45 | A - 8020 Graz
Mail/XMPP: sven.schwe...@tao.at | +43 (0)680 301 7167
http://software.tao.at



signature.asc
Description: OpenPGP digital signature


Re: [SOGo] ganz boesartiges how-to

2015-09-30 Thread mourik jan heupink

I found the original anouncement in the archives:


Hi,

I've just uploaded dovecot 2.1.17 to our repos for debian wheezy (both 
amd64 and i386).  I did this since the package shipped with wheezy 
(2.1.7) contains a bug[1] in the handling of sieve commands that was 
fixed upstream back in February 2013. Unfortunately, the commit never 
found its way back to debian stable.


The package is essentially a rebuild of the package found in debian 
jessie, no patch added.


If for some reason you don't want to use this package, you'll need to 
manually exclude it.


Thanks.

[1] http://sogo.nu/bugs/view.php?id=2230
[2] http://hg.rename-it.nl/dovecot-2.1-pigeonhole/rev/32d178f5e1a2


--
users@sogo.nu
https://inverse.ca/sogo/lists


Re: [SOGo] ganz boesartiges how-to

2015-09-30 Thread Peter Beck
On 09/30/2015 08:58 AM, Sven Schwedas wrote:
> But I'm curious why the SOGo repository
> includes Dovecot builds, too. Just to compile them against newer library
> versions, or are they patched in some way?

on Jessie it's not the case:

dovecot-core:
  Installed: 1:2.2.13-12~deb8u1
  Candidate: 1:2.2.13-12~deb8u1
  Version table:
 *** 1:2.2.13-12~deb8u1 0
500 http://ftp.ch.debian.org/debian/ jessie/main amd64 Packages
100 /var/lib/dpkg/status

dovecot-imapd:
  Installed: 1:2.2.13-12~deb8u1
  Candidate: 1:2.2.13-12~deb8u1
  Version table:
 *** 1:2.2.13-12~deb8u1 0
500 http://ftp.ch.debian.org/debian/ jessie/main amd64 Packages
100 /var/lib/dpkg/status

etc...
-- 
users@sogo.nu
https://inverse.ca/sogo/lists


[SOGo] ganz boesartiges how-to

2015-09-29 Thread Christian Eichert

Nachdem man auf auf

http://www.sogo.nu/nc/support/faq/article/how-to-install-sogo-on-debian.html

belehr wird die sogo keyring zu installieren wird man aufgefordert zu 
updaten
Die Sogo Repository  "updatet" dann unerwünschterweise pakete aus der 
standard debian repository

und bricht installationen

Holen: 1 http://inverse.ca/debian/ wheezy/wheezy dovecot-managesieved 
amd64 1:2.1.17-2~inverse11 [417 kB]
Holen: 2 http://inverse.ca/debian/ wheezy/wheezy dovecot-sieve amd64 
1:2.1.17-2~inverse11 [623 kB]
Holen: 3 http://inverse.ca/debian/ wheezy/wheezy dovecot-pop3d amd64 
1:2.1.17-2~inverse11 [388 kB]
Holen: 4 http://inverse.ca/debian/ wheezy/wheezy dovecot-pgsql amd64 
1:2.1.17-2~inverse11 [369 kB]
Holen: 5 http://inverse.ca/debian/ wheezy/wheezy dovecot-mysql amd64 
1:2.1.17-2~inverse11 [366 kB]
Holen: 6 http://inverse.ca/debian/ wheezy/wheezy dovecot-ldap amd64 
1:2.1.17-2~inverse11 [380 kB]
Holen: 7 http://inverse.ca/debian/ wheezy/wheezy dovecot-imapd amd64 
1:2.1.17-2~inverse11 [452 kB]
Holen: 8 http://inverse.ca/debian/ wheezy/wheezy dovecot-gssapi amd64 
1:2.1.17-2~inverse11 [365 kB]
Holen: 9 http://inverse.ca/debian/ wheezy/wheezy dovecot-core amd64 
1:2.1.17-2~inverse11 [3.028 kB]


Ich weiss nicht wie ich das einstufen soll.
Ist das ein Angriff ?

--
users@sogo.nu
https://inverse.ca/sogo/lists