-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sun, 01 Jan 2012 18:10:58 +0000 Source: cyrus-imapd-2.2 Binary: cyrus-common-2.2 cyrus-doc-2.2 cyrus-imapd-2.2 cyrus-pop3d-2.2 cyrus-admin-2.2 cyrus-murder-2.2 cyrus-nntpd-2.2 cyrus-clients-2.2 cyrus-dev-2.2 libcyrus-imap-perl22 Architecture: kfreebsd-i386 Version: 2.2.13-19+squeeze3 Distribution: squeeze-security Urgency: high Maintainer: kfreebsd-i386 Build Daemon (finzi) Changed-By: Nico Golde Description: cyrus-admin-2.2 - Cyrus mail system - administration tools cyrus-clients-2.2 - Cyrus mail system (test clients) cyrus-common-2.2 - Cyrus mail system - common files cyrus-dev-2.2 - Cyrus mail system (developer files) cyrus-doc-2.2 - Cyrus mail system - documentation files cyrus-imapd-2.2 - Cyrus mail system - IMAP support cyrus-murder-2.2 - Cyrus mail system (proxies and aggregator) cyrus-nntpd-2.2 - Cyrus mail system (NNTP support) cyrus-pop3d-2.2 - Cyrus mail system - POP3 support libcyrus-imap-perl22 - Interface to Cyrus imap client imclient library Changes: cyrus-imapd-2.2 (2.2.13-19+squeeze3) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix possible NULL pointer dereference via crafted message reference id caused by a missing sanitizing of the mail headers. This can be exploited from a client making use of the IMAP threading feature (CVE-2011-3481). Checksums-Sha1: 07076f331dbfbc22cbbf02e6d77a6cd9e13fa1be 5607954 cyrus-common-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 1d4eb3b555717f71e399a18b5230ceae9a18ea05 923720 cyrus-imapd-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 699e5d6d96bd8451117d50e67586d4d8ad6b3ba0 275946 cyrus-pop3d-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb a709ed211e002b390ffc459ebc56bf1af8d9b6fe 1114240 cyrus-murder-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 5a3399d70222ed3213882d4e48f3757d885acd18 597484 cyrus-nntpd-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb e90ac0bf127a42bd037e8b5021af98b76beadeb8 132692 cyrus-clients-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 55c3249e7b26a9c8bbe3eb01eaa5eb20acb0b426 266058 cyrus-dev-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 3e5f87181ef7244fb8f5a8bd17dcc3a3aed748ef 184024 libcyrus-imap-perl22_2.2.13-19+squeeze3_kfreebsd-i386.deb Checksums-Sha256: 60c962d75f248da815f0212869096f239718ca2d81c3bf4813e0beb20944802b 5607954 cyrus-common-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 335488535d721cfeec10a79bcceca24cd7bbf4087e798e28d6cd38135950cd2f 923720 cyrus-imapd-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb ed96690803025230f4d798dfd249e90925ec53a4ec2424ae6b212d16411b6d8a 275946 cyrus-pop3d-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb db0012634466b220194dded121b2182ba111459359b3093aa9da6349f106b1d1 1114240 cyrus-murder-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb febf4e82750c6d747f2e26ac718f01e4d99b0206dde54ca71a0f7127175e0336 597484 cyrus-nntpd-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb aab531b9c2e1040ff006ea2aff0c19bb629f5acc25897e7f39ab2bfeaf1761c5 132692 cyrus-clients-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb a6273f232964ab89259a9aa604ccaf9fba21129e46206ea5f302ae5fbd8cafdd 266058 cyrus-dev-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb dd81badf92345c6eb718f08cf7c3f85b986df3fc1d6a4d849dc48e6b727a820e 184024 libcyrus-imap-perl22_2.2.13-19+squeeze3_kfreebsd-i386.deb Files: 0a42fbe1a89ef138dd93c678c72c613e 5607954 mail extra cyrus-common-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 8d152352ef7a7c75047e7e50a1b887d5 923720 mail extra cyrus-imapd-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 078d8da60e3e39a82304c7a65bb8201d 275946 mail extra cyrus-pop3d-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb a13251c62cc3f32294297b008d62508b 1114240 mail extra cyrus-murder-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 0cdca378782fcbde2af021c4ecb06a4a 597484 mail extra cyrus-nntpd-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 1671573f6beb3033816b60b3da33f3b2 132692 mail extra cyrus-clients-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 8c574b78a2f208b408c47a18ec132c3c 266058 devel extra cyrus-dev-2.2_2.2.13-19+squeeze3_kfreebsd-i386.deb 926bea30e1d9d1c89dc60a111aa7940d 184024 perl extra libcyrus-imap-perl22_2.2.13-19+squeeze3_kfreebsd-i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/kFreeBSD) iQIcBAEBAgAGBQJPASEEAAoJEGTibMHYWaUAJ7cP/2IapLDbqYGwmCaQoyUN6Acm h3yU09vWm3us42Tsb4TT50xaamyR4wryCjKuqsHKfKfSZtbj2cbYQ4LLL3W5vphM IUTjGeZ5LD0yrE+JrDKvbJ4GNP3JbLkM4BQr2KYsHqROF1mYcRT0BlKc6djFBkpg 9epHIzqr2pFwb5/z3BDUFzobLsaxIYHKybJzYmgXDJ1032Kz/AC7c/qUp2NKuvMt PD2cmEKzMD+pXlDCalX9rCtIrzIJ2Ly9qbayLgkdTwgspMmuzj4jn89SHmk4SoOC 3PXz9eDH3thEMvtwzhNG8jJD2J9L7jdjrq7ACKLx+rvX7ndL1eaNlXMBXG/QaWV6 VmskxGyDlrSdlj9mkvlRp2atgs0GbOh9FsOWX50k58/cZ3bjJsNNA84B7qRmpbZs yPnrOTa1b/ezrPYE73BRQkLEfDwKUlJH4y2FSiqnZBMvriCU+DcOC7ONhKHeHmuo 5rYyaCh/HhW2w68H5IaVm306T+96PY/fjfMteDYGkUdE73KXLjhYmsiV+Ji41OoJ gudjcgVzjHlehNeuo0LdK/TL689uW38fPLpsae9D21YRR18R65w94LGBPgJeEGNq XE9cMzzzscrd3MakGbwVhgkyqUVwRterZeQOHWgLoQ6UOjjWZh9K8DuZqL9pfdTl TVgqh7yG23H8o5Onf69F =ZY5X -----END PGP SIGNATURE-----