-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 01 Jan 2012 18:10:58 +0000 Source: cyrus-imapd-2.2 Binary: cyrus-common-2.2 cyrus-doc-2.2 cyrus-imapd-2.2 cyrus-pop3d-2.2 cyrus-admin-2.2 cyrus-murder-2.2 cyrus-nntpd-2.2 cyrus-clients-2.2 cyrus-dev-2.2 libcyrus-imap-perl22 Architecture: powerpc Version: 2.2.13-19+squeeze3 Distribution: squeeze-security Urgency: high Maintainer: powerpc Build Daemon (poulenc) Changed-By: Nico Golde Description: cyrus-admin-2.2 - Cyrus mail system - administration tools cyrus-clients-2.2 - Cyrus mail system (test clients) cyrus-common-2.2 - Cyrus mail system - common files cyrus-dev-2.2 - Cyrus mail system (developer files) cyrus-doc-2.2 - Cyrus mail system - documentation files cyrus-imapd-2.2 - Cyrus mail system - IMAP support cyrus-murder-2.2 - Cyrus mail system (proxies and aggregator) cyrus-nntpd-2.2 - Cyrus mail system (NNTP support) cyrus-pop3d-2.2 - Cyrus mail system - POP3 support libcyrus-imap-perl22 - Interface to Cyrus imap client imclient library Changes: cyrus-imapd-2.2 (2.2.13-19+squeeze3) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix possible NULL pointer dereference via crafted message reference id caused by a missing sanitizing of the mail headers. This can be exploited from a client making use of the IMAP threading feature (CVE-2011-3481). Checksums-Sha1: 667fedc599ce72c6ba3f865783bb0b9ceeab48e8 5633262 cyrus-common-2.2_2.2.13-19+squeeze3_powerpc.deb ff373b2883fa3a8d89b8d106990145e7cd69c539 929218 cyrus-imapd-2.2_2.2.13-19+squeeze3_powerpc.deb 669cfce24188844c101912dd5f91e61913e64ec0 276842 cyrus-pop3d-2.2_2.2.13-19+squeeze3_powerpc.deb ee1cdd086b37be0216c9ec3aff1d45d98ebfc4a7 1119876 cyrus-murder-2.2_2.2.13-19+squeeze3_powerpc.deb fa028d9754a8d42b45a588810cf3ffb7d38c7200 601608 cyrus-nntpd-2.2_2.2.13-19+squeeze3_powerpc.deb ff3499b59c11cb7c004e41e0fd4df0addd53ab8d 134392 cyrus-clients-2.2_2.2.13-19+squeeze3_powerpc.deb 30de3dbb2c961120a77b42bd5f15b49db8e845ca 268050 cyrus-dev-2.2_2.2.13-19+squeeze3_powerpc.deb c418d2539a2321b7423f6b3d0f3b77ada66ac7be 189528 libcyrus-imap-perl22_2.2.13-19+squeeze3_powerpc.deb Checksums-Sha256: 39d8beef60ffc3cc551a55b8f30b042f6dcbcdc69356a27a346a51caccaf9f6b 5633262 cyrus-common-2.2_2.2.13-19+squeeze3_powerpc.deb 4a8d1e4741eba689430a3a82a5e8bb1ed64f0a5195deb350e2c7538b273d619d 929218 cyrus-imapd-2.2_2.2.13-19+squeeze3_powerpc.deb 689f47a291399b123b247766291f0de9cf4a22db90832137087c54193a53e45f 276842 cyrus-pop3d-2.2_2.2.13-19+squeeze3_powerpc.deb c5ebf9cd9238861c4a51b8af8953eab8e06bbcc746d37c34a9b82ada2a4138fc 1119876 cyrus-murder-2.2_2.2.13-19+squeeze3_powerpc.deb b2318cb1786834dcf8042db932217b60d92d5638e587f360b2083c651e3c1388 601608 cyrus-nntpd-2.2_2.2.13-19+squeeze3_powerpc.deb 0f53deff6d689bbf12a802d9ab33f4211d2c73278a46b60ff82d2bc1382c18a6 134392 cyrus-clients-2.2_2.2.13-19+squeeze3_powerpc.deb 0e780f68040182b331e3aed245c8573f53c11a09991e10be64cda0d6c55d2ee1 268050 cyrus-dev-2.2_2.2.13-19+squeeze3_powerpc.deb bda7e4fcff72cdd84453429844937405a9a8bd61512888acde3e31496670800a 189528 libcyrus-imap-perl22_2.2.13-19+squeeze3_powerpc.deb Files: 0d7ac181dd570a0c57c3b4147861c144 5633262 mail extra cyrus-common-2.2_2.2.13-19+squeeze3_powerpc.deb 967d0cba7909b4212fe776c060b7cd23 929218 mail extra cyrus-imapd-2.2_2.2.13-19+squeeze3_powerpc.deb df820b6f6e030f883287a550abdcddd6 276842 mail extra cyrus-pop3d-2.2_2.2.13-19+squeeze3_powerpc.deb 55290d4c831503191638eded8e0fbb33 1119876 mail extra cyrus-murder-2.2_2.2.13-19+squeeze3_powerpc.deb a8f28b6ab08525f2482959567847fe9c 601608 mail extra cyrus-nntpd-2.2_2.2.13-19+squeeze3_powerpc.deb d0a18675e0da07dbadf4e6aa7c9a8345 134392 mail extra cyrus-clients-2.2_2.2.13-19+squeeze3_powerpc.deb a62582c59bfb7efe5d8c87da5ec2640f 268050 devel extra cyrus-dev-2.2_2.2.13-19+squeeze3_powerpc.deb fdcd9d55580bda3e5c8d9996c5b4751d 189528 perl extra libcyrus-imap-perl22_2.2.13-19+squeeze3_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJPAK8FAAoJEAEba0y9vvHNgrAQAMft9eUJM2rwk0+Np0hCWHNv LlIdrh67th1nsmBjSiMziwEUn3elpaImkN0noCltKmQsU98ldSTkYwSV7NN78Rmw iAeHO6gQhBB8TEsPdtDRqWteJjZq/oBJfYRYL23TnI6HYkAHFSkJi1jWxP1SVjRs 1i3U/LiIFh2/VOOYJA5nXysB99W29lse3YziHKwyV6SXi1poAAUxUheR+F5NIQrH QrGLsfOz066mV5EY2M6oJeGggwQcl7Bp6jH4HJkjLI/74r3ABaP5ajJEFeLTrxDt 2II3JOspsTw5wHEpANnB/+p23Onf+Kuwvv9brL7q2mz1BfVqjQcXspho5fZjlTBx G4aaU6sWhdzPFHSIPLVlRZ2PdQRUKUchPCb26NsfJb+XmwHiFEj8Is+JXbEG6zhD JVuwy+fbAmh8VcrILb+k4uoe9xzomjOEEbety1kGosjBuG2GrDPLSbgEMJMCuIg3 5bAF9PaAc2VFWSnSJu3yOG9i1bkk+LCa7xIQbPuTF1XkucSm9uybEOBnkJnDrcu2 +IYSpFNlM1biUhbSiT2S0YWCvsc6fumyjWB78I4k2kqtm/Z7v7Oc2sFVpEvt99/H qlh5+sw8gx0VgXqGRSXRA/evbb/56nmDJQ7AcXhutyJlnegbNaKEchZ3w/fkp/BW DxWAod7tAsw5ybt1zWEw =kajt -----END PGP SIGNATURE-----