Format: 1.8 Date: Mon, 31 Jan 2011 13:53:14 -0500 Source: dovecot Binary: dovecot-common dovecot-dev dovecot-imapd dovecot-pop3d dovecot-postfix dovecot-dbg Architecture: sparc Version: 1:1.2.9-1ubuntu6.3 Distribution: lucid Urgency: low Maintainer: Ubuntu/sparc Build Daemon Changed-By: Marc Deslauriers Description: dovecot-common - secure mail server that supports mbox and maildir mailboxes dovecot-dbg - debug symbols for Dovecot dovecot-dev - header files for the dovecot mail server dovecot-imapd - secure IMAP server that supports mbox and maildir mailboxes dovecot-pop3d - secure POP3 server that supports mbox and maildir mailboxes dovecot-postfix - full mail server stack provided by Ubuntu server team Changes: dovecot (1:1.2.9-1ubuntu6.3) lucid-security; urgency=low . * SECURITY UPDATE: information disclosure via newly created mailboxes with incorrect ACLs - debian/patches/CVE-2010-3304.patch: verify the directory isn't the same as the INBOX's directory in src/plugins/acl/acl-backend-vfile.c. - CVE-2010-3304 * SECURITY UPDATE: ACL bypass via incorrect ACL merging - debian/patches/CVE-2010-370x.patch: fix logic of merging multiple ACLs in src/plugins/acl/{acl-api.h,acl-backend-vfile.c,acl-backend.c, acl-cache.c}. - CVE-2010-3706 - CVE-2010-3707 * SECURITY UPDATE: restriction bypass via mailbox ACL changing - debian/patches/CVE-2010-3779.patch: don't give admin rights to all owner mailboxes in src/plugins/acl/acl-backend-vfile.c. - CVE-2010-3779 * SECURITY UPDATE: denial of service via many simultaneous disconnects. - debian/patches/CVE-2010-3780.patch: don't die after three failed writes to log in src/lib/failures.c. - CVE-2010-3780 * debian/control: removed linux-kernel-headers from Build-Conflicts to resolve building with sbuild. * This update does not contain the changes from 1:1.2.9-1ubuntu6.2 that was in -proposed. Checksums-Sha1: a5b49559e06f0ddb650bd8a5157169bc44f6bd1b 5315260 dovecot-common_1.2.9-1ubuntu6.3_sparc.deb b51ebb6d2176fae20c760231cc87b1f009ae82cb 656468 dovecot-dev_1.2.9-1ubuntu6.3_sparc.deb d0bc8765d27d8aa3c05ab693f089012bd35e7fc9 1189960 dovecot-imapd_1.2.9-1ubuntu6.3_sparc.deb 93b563cb75eb7abfc6e4670e94dcda275c555e21 1081132 dovecot-pop3d_1.2.9-1ubuntu6.3_sparc.deb 55dbe888aaa4e26c345284b874c6b42e4f651b5a 14201530 dovecot-dbg_1.2.9-1ubuntu6.3_sparc.deb Checksums-Sha256: 8103ec6449b4299b625d96d36ebdcc61bc735a6cd16f95ff990ae3459a664f2d 5315260 dovecot-common_1.2.9-1ubuntu6.3_sparc.deb 7a5f05976adfc94aca6beae8a625165aa208a176077b32c336dde1e1892b04f0 656468 dovecot-dev_1.2.9-1ubuntu6.3_sparc.deb 34118f8d880895096b7ab202369b1bbb5543ee4d98c617b6f7b3f1d4a499fb42 1189960 dovecot-imapd_1.2.9-1ubuntu6.3_sparc.deb 393223c45df0b5e746906b381f061cc6989128333ccdaa9994a8aced0d56d898 1081132 dovecot-pop3d_1.2.9-1ubuntu6.3_sparc.deb cf21d6f3f709c752c71187cf47fc21923094f55b3d08a76695fd41524c96f364 14201530 dovecot-dbg_1.2.9-1ubuntu6.3_sparc.deb Files: 91239166c042cb1776f53aec4942bd9c 5315260 mail optional dovecot-common_1.2.9-1ubuntu6.3_sparc.deb d61d6e6bde0d48346018a432badee15e 656468 mail optional dovecot-dev_1.2.9-1ubuntu6.3_sparc.deb 8c93283a7425f5ffb2cba844edf6db56 1189960 mail optional dovecot-imapd_1.2.9-1ubuntu6.3_sparc.deb ca8c6c4944e22f23fcdde4b55374e41d 1081132 mail optional dovecot-pop3d_1.2.9-1ubuntu6.3_sparc.deb 400e1594cc8dc50607a6e30bc2409910 14201530 debug extra dovecot-dbg_1.2.9-1ubuntu6.3_sparc.deb Original-Maintainer: Dovecot Maintainers