Format: 1.8 Date: Fri, 12 Apr 2024 11:03:05 -0400 Source: amavisd-new Binary: amavisd-new amavisd-new-postfix Built-For-Profiles: noudeb Architecture: all Version: 1:2.13.0-3ubuntu1.1 Distribution: mantic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: amavisd-new - Interface between MTA and virus scanner/content filters amavisd-new-postfix - part of Ubuntu mail stack provided by Ubuntu server team Changes: amavisd-new (1:2.13.0-3ubuntu1.1) mantic-security; urgency=medium . * SECURITY UPDATE: incorrect check via multiple boundary parameters - debian/patches/CVE-2024-28054-1.patch: add CC_UNCHECKED,3 content category in conf/amavisd.conf, lib/Amavis.pm, lib/Amavis/Conf.pm, lib/Amavis/Unpackers.pm, lib/Amavis/Unpackers/MIME.pm, lib/Amavis/Unpackers/Part.pm, t/Amavis/Unpackers/MIMETest.pm. - debian/patches/CVE-2024-28054-2.patch: use MIME::Entity->ambiguous_content if available in .gitlab-ci.yml, lib/Amavis/Unpackers/MIME.pm. - debian/patches/CVE-2024-28054-3.patch: describe CVE-2024-28054 in README_FILES/README.CVE-2024-28054. - CVE-2024-28054 Checksums-Sha1: 79380d0275e612ec53de2bb562e625c3a4d9fcd9 4552 amavisd-new-postfix_2.13.0-3ubuntu1.1_all.deb c32acda87e4259d7b66bcb283fd3246f823e4edb 635208 amavisd-new_2.13.0-3ubuntu1.1_all.deb 1d0953a66c225e8e69547de9479f2af33ccc31d6 12554 amavisd-new_2.13.0-3ubuntu1.1_amd64.buildinfo Checksums-Sha256: ec1a07cb45c2ee446538d8a21e09630c224c1a2d335911892538b60d4c888918 4552 amavisd-new-postfix_2.13.0-3ubuntu1.1_all.deb 4276a2fd9e2a2353a39e09357a5cfdd67347deab185b294b0d11f52d23da2282 635208 amavisd-new_2.13.0-3ubuntu1.1_all.deb ec918a9952ba368edda37bb1bd6bd31917cb8d5e2a1c59c3e7de79d8835485f9 12554 amavisd-new_2.13.0-3ubuntu1.1_amd64.buildinfo Files: 566def145d3f9acc031c112f735eb1c4 4552 mail optional amavisd-new-postfix_2.13.0-3ubuntu1.1_all.deb 64f5f5f9f2cbeab9c4f12f51c5046b06 635208 mail optional amavisd-new_2.13.0-3ubuntu1.1_all.deb 3bb3818bb506517ec75aa51693ef630c 12554 mail optional amavisd-new_2.13.0-3ubuntu1.1_amd64.buildinfo Original-Maintainer: Brian May