-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sun, 01 Jan 2012 18:10:58 +0000 Source: cyrus-imapd-2.2 Binary: cyrus-common-2.2 cyrus-doc-2.2 cyrus-imapd-2.2 cyrus-pop3d-2.2 cyrus-admin-2.2 cyrus-murder-2.2 cyrus-nntpd-2.2 cyrus-clients-2.2 cyrus-dev-2.2 libcyrus-imap-perl22 Architecture: kfreebsd-amd64 Version: 2.2.13-19+squeeze3 Distribution: squeeze-security Urgency: high Maintainer: kfreebsd-amd64 Build Daemon (fasch) Changed-By: Nico Golde Description: cyrus-admin-2.2 - Cyrus mail system - administration tools cyrus-clients-2.2 - Cyrus mail system (test clients) cyrus-common-2.2 - Cyrus mail system - common files cyrus-dev-2.2 - Cyrus mail system (developer files) cyrus-doc-2.2 - Cyrus mail system - documentation files cyrus-imapd-2.2 - Cyrus mail system - IMAP support cyrus-murder-2.2 - Cyrus mail system (proxies and aggregator) cyrus-nntpd-2.2 - Cyrus mail system (NNTP support) cyrus-pop3d-2.2 - Cyrus mail system - POP3 support libcyrus-imap-perl22 - Interface to Cyrus imap client imclient library Changes: cyrus-imapd-2.2 (2.2.13-19+squeeze3) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix possible NULL pointer dereference via crafted message reference id caused by a missing sanitizing of the mail headers. This can be exploited from a client making use of the IMAP threading feature (CVE-2011-3481). Checksums-Sha1: 197914886f7567cac38647308bf93b895d0cdc4b 5821676 cyrus-common-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 5088ffee7e92d576651397f7c3d7090afe9689cb 960704 cyrus-imapd-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 562287604d19a61a25acc9967743159d4d7636a3 286634 cyrus-pop3d-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 8cb4927aa9d5edda1608bacbe190827217626b68 1158750 cyrus-murder-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 27b7ba616837fe0f054c28618f966f2b06dbbd0d 620400 cyrus-nntpd-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 62b3ef116f72166ff491d0038f133eab176abd81 137154 cyrus-clients-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb b69e5a4baf31934f8ca497f99c1e06d50068df6b 273974 cyrus-dev-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb c1b0774ccb623139a27d4825723b79794bb448c0 192372 libcyrus-imap-perl22_2.2.13-19+squeeze3_kfreebsd-amd64.deb Checksums-Sha256: 742a882b0f274adeb527a3a9742ce3c09fbc6d36d93fc6f2e436f66079fb0f4c 5821676 cyrus-common-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb c32e7bf7017f2d1c42a2e973a528eae942388fb17d8f312dfad69e19c9440e21 960704 cyrus-imapd-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 7a898c3515203eaf6afcf9070f6e0c1262adc059b6ba5130e53cbb6f3ecc55b5 286634 cyrus-pop3d-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 8a7a8463915bce845679e3e8ed68fc0c5f7772a0458b1c302591d47ad78a19d7 1158750 cyrus-murder-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb e8162756f2af97fd2e1f8b3cf7d757f2f19539a44a299e0a22490a28c22e2959 620400 cyrus-nntpd-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 510e33b6d7a1b990f54366f541c9ecb8a2a961404d489526d958c035a05da02c 137154 cyrus-clients-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb d744174031f85e0057691ddb2ae8f9e9b8f49c2c01f79e902cfa1e5330a24d3a 273974 cyrus-dev-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 863901616ed20196205ea4923067f3d14d2a3199cf8c99874f61f9717c9d5dba 192372 libcyrus-imap-perl22_2.2.13-19+squeeze3_kfreebsd-amd64.deb Files: f2a836e5b63ff4efcd3a810df6ec503f 5821676 mail extra cyrus-common-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb b1c1c3f8bc80c79b9aaaeaf326a4bf1b 960704 mail extra cyrus-imapd-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 1223621bb11a771003008b4ae98bbd2c 286634 mail extra cyrus-pop3d-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 822a66e830ee79cb16458ff9b698e656 1158750 mail extra cyrus-murder-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 40e7817168ce656f6175170b19338e37 620400 mail extra cyrus-nntpd-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 2a6544524f8f8da8a5fe7354d90b7ab6 137154 mail extra cyrus-clients-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 6e6c912cf9af6a10b9507cf2c2296d0a 273974 devel extra cyrus-dev-2.2_2.2.13-19+squeeze3_kfreebsd-amd64.deb 863204fa69a247a8d054d2c909cb854b 192372 perl extra libcyrus-imap-perl22_2.2.13-19+squeeze3_kfreebsd-amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/kFreeBSD) iQIbBAEBAgAGBQJPASDlAAoJELV0nKsIaKwSSHoP93cPDrRY7LEvaLrHJjq5Irel VStqzyJUSeGDU39berkhedaOgCUS5rHkjahuwKOmYmqfYVt//ezl8B77QLbIjBD0 PR5rtzQL9mqya5q3tywL/bm5F+PefnbLVBwHfZNL2VUa//1S3h/Kua9C7POdZcLg 5zfU4eGMTeDH1MSEhiU9K3Ezwxs6Px0MgmIv5SmPbxoI094ntCWRJCKUELHEkceu IQLyHlQTMKx/9snQLPFJIkSx9wSpGGP70K8bWv4hjz/eeHY0qeQgmWvc3RAVfBsU xYgKClQ2YePKScQCO8LSxnUwAeOUv00HY6vXPrjlTKznFKGiKFfmIZYBM3Y3b9SZ S28ug6iDBcaFud6iSpr5c80ZyUbQn+Q2UYVkAxDClIBcAWqnWDnO56dbJpCt1BsO 8WSBVMtE0Wn3/PNCjBrd4An63LHtlrBYQl4m7VuHBRyx6O4BTmbSY73NQVMQ5kPx SnI6RVitQRtYPYLfqfv9I9Aj80sprLdrhIWMFjVmuEll1vUh4BZ7G6MZcTm9XtYw OFM0kJR3rRTLWStppXZ9j3j886nYDqQ1ibClG8iqphpDP/y7n48jPPUBfBBClY+k J2ZTBzl3UISxPyGm+FV2HG8W5eHsdFUtm39JLBHiJPT0zK7z7CF/St6Cv8mhAgzR +jEppBhpzc4mzAeMFwE= =FFcI -----END PGP SIGNATURE-----