Format: 1.8 Date: Mon, 10 Jan 2011 15:29:47 -0600 Source: dovecot Binary: dovecot-common dovecot-dev dovecot-imapd dovecot-pop3d mail-stack-delivery dovecot-postfix dovecot-dbg Architecture: all i386 Version: 1:1.2.12-1ubuntu8.1 Distribution: maverick Urgency: low Maintainer: Ubuntu/i386 Build Daemon Changed-By: Marc Deslauriers Description: dovecot-common - secure mail server that supports mbox and maildir mailboxes dovecot-dbg - debug symbols for Dovecot dovecot-dev - header files for the dovecot mail server dovecot-imapd - secure IMAP server that supports mbox and maildir mailboxes dovecot-pop3d - secure POP3 server that supports mbox and maildir mailboxes dovecot-postfix - mail server delivery agent stack provided by Ubuntu server team mail-stack-delivery - mail server delivery agent stack provided by Ubuntu server team Changes: dovecot (1:1.2.12-1ubuntu8.1) maverick-security; urgency=low . * SECURITY UPDATE: information disclosure via newly created mailboxes with incorrect ACLs - debian/patches/CVE-2010-3304.patch: verify the directory isn't the same as the INBOX's directory in src/plugins/acl/acl-backend-vfile.c. - CVE-2010-3304 * SECURITY UPDATE: ACL bypass via incorrect ACL merging - debian/patches/CVE-2010-370x.patch: fix logic of merging multiple ACLs in src/plugins/acl/{acl-api.h,acl-backend-vfile.c,acl-backend.c, acl-cache.c}. - CVE-2010-3706 - CVE-2010-3707 * SECURITY UPDATE: restriction bypass via mailbox ACL changing - debian/patches/CVE-2010-3779.patch: don't give admin rights to all owner mailboxes in src/plugins/acl/acl-backend-vfile.c. - CVE-2010-3779 * SECURITY UPDATE: denial of service via many simultaneous disconnects. - debian/patches/CVE-2010-3780.patch: don't die after three failed writes to log in src/lib/failures.c. - CVE-2010-3780 * debian/control: removed linux-kernel-headers from Build-Conflicts to resolve building with sbuild. Checksums-Sha1: fb98624c754e285f9d600f757eedb003ead23536 525996 mail-stack-delivery_1.2.12-1ubuntu8.1_all.deb 57767806924dabb9e322f9635dbb2d99745dc1d4 522198 dovecot-postfix_1.2.12-1ubuntu8.1_all.deb e41023a4644d3d3c4b86607515d57cba5f0f6c98 5246496 dovecot-common_1.2.12-1ubuntu8.1_i386.deb 7a26b530060da717f654cc15eecdfbd45fffa1e4 664386 dovecot-dev_1.2.12-1ubuntu8.1_i386.deb bc16691e676845c2aafddb8605e2f510a329bdc3 1166874 dovecot-imapd_1.2.12-1ubuntu8.1_i386.deb 0c277cfa62ef0ee5676fe38e98b7ff7d1627100d 1065500 dovecot-pop3d_1.2.12-1ubuntu8.1_i386.deb 6fa536d46068a83c6cedf928400683f2838e968e 15173598 dovecot-dbg_1.2.12-1ubuntu8.1_i386.deb Checksums-Sha256: fdc50730c29f875aecca64aead8645c5d8db3489ed42182c48fd4fae9ba4838d 525996 mail-stack-delivery_1.2.12-1ubuntu8.1_all.deb 596f6fcfa21a8bd4bbc87892ed3d0eae8502a6a62667a39674cb2777e4c2c114 522198 dovecot-postfix_1.2.12-1ubuntu8.1_all.deb 74ba5ec7663abd62a0d4e176f44ed7322b63345ec3a07fdc07b5d149fe9547ac 5246496 dovecot-common_1.2.12-1ubuntu8.1_i386.deb fbf73a8aa3c524d9eeeac214bb93b18e01f5f7413b375c468066affeb9447143 664386 dovecot-dev_1.2.12-1ubuntu8.1_i386.deb 7aa957fdb06394da1003ab22169d979a78b74a59790aaa71453515d488cf1365 1166874 dovecot-imapd_1.2.12-1ubuntu8.1_i386.deb 50803da0ef284d0c5c19f1bb224d5e2e3aff8b3a89aaf02d1134a6adb0314b4b 1065500 dovecot-pop3d_1.2.12-1ubuntu8.1_i386.deb c3408ec414ba5d6c2198b42a4c3f28e0d5a34499cdf1988db57e126799677a96 15173598 dovecot-dbg_1.2.12-1ubuntu8.1_i386.deb Files: 063bf23bee428827de152998fce3855f 525996 mail optional mail-stack-delivery_1.2.12-1ubuntu8.1_all.deb b5ee6b912defe13e6899cba856c03836 522198 mail optional dovecot-postfix_1.2.12-1ubuntu8.1_all.deb 17d4a818b64e265f244a0110d027a33d 5246496 mail optional dovecot-common_1.2.12-1ubuntu8.1_i386.deb c8b2ffd0f0ae892fd792d71b11f29658 664386 mail optional dovecot-dev_1.2.12-1ubuntu8.1_i386.deb 2d6b53c0113f91db83d0497d878fccb4 1166874 mail optional dovecot-imapd_1.2.12-1ubuntu8.1_i386.deb 17fddc68c95dbfdce3d74812a707eca3 1065500 mail optional dovecot-pop3d_1.2.12-1ubuntu8.1_i386.deb dbadcbf9c428b908f074f29b9687fb1f 15173598 debug extra dovecot-dbg_1.2.12-1ubuntu8.1_i386.deb Original-Maintainer: Dovecot Maintainers