[ubuntu/bionic-proposed] dovecot 1:2.2.33.2-1ubuntu3 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Fri Feb 23 15:20:19 UTC 2018


dovecot (1:2.2.33.2-1ubuntu3) bionic; urgency=medium

  * SECURITY UPDATE: Memory leak that can cause crash due to memory exhaustion
    - debian/patches/CVE-2017-15132.patch: fix memory leak in
      auth_client_request_abort() in src/lib-auth/auth-client-request.c.
    - debian/patches/CVE-2017-15132-additional.patch: remove request after
      abort in src/lib-auth/auth-client-request.c,
      src/lib-auth/auth-server-connection.c,
      src/lib-auth/auth-serser-connection.h.
    - CVE-2017-15132

Date: Fri, 23 Feb 2018 09:49:11 -0500
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/dovecot/1:2.2.33.2-1ubuntu3
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 23 Feb 2018 09:49:11 -0500
Source: dovecot
Binary: dovecot-core dovecot-dev dovecot-imapd dovecot-pop3d dovecot-lmtpd dovecot-managesieved dovecot-pgsql dovecot-mysql dovecot-sqlite dovecot-ldap dovecot-gssapi dovecot-sieve dovecot-solr mail-stack-delivery
Architecture: source
Version: 1:2.2.33.2-1ubuntu3
Distribution: bionic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Leonidas S. Barbosa <leo.barbosa at canonical.com>
Description:
 dovecot-core - secure POP3/IMAP server - core files
 dovecot-dev - secure POP3/IMAP server - header files
 dovecot-gssapi - secure POP3/IMAP server - GSSAPI support
 dovecot-imapd - secure POP3/IMAP server - IMAP daemon
 dovecot-ldap - secure POP3/IMAP server - LDAP support
 dovecot-lmtpd - secure POP3/IMAP server - LMTP server
 dovecot-managesieved - secure POP3/IMAP server - ManageSieve server
 dovecot-mysql - secure POP3/IMAP server - MySQL support
 dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support
 dovecot-pop3d - secure POP3/IMAP server - POP3 daemon
 dovecot-sieve - secure POP3/IMAP server - Sieve filters support
 dovecot-solr - secure POP3/IMAP server - Solr support
 dovecot-sqlite - secure POP3/IMAP server - SQLite support
 mail-stack-delivery - mail server delivery agent stack provided by Ubuntu server team
Changes:
 dovecot (1:2.2.33.2-1ubuntu3) bionic; urgency=medium
 .
   * SECURITY UPDATE: Memory leak that can cause crash due to memory exhaustion
     - debian/patches/CVE-2017-15132.patch: fix memory leak in
       auth_client_request_abort() in src/lib-auth/auth-client-request.c.
     - debian/patches/CVE-2017-15132-additional.patch: remove request after
       abort in src/lib-auth/auth-client-request.c,
       src/lib-auth/auth-server-connection.c,
       src/lib-auth/auth-serser-connection.h.
     - CVE-2017-15132
Checksums-Sha1:
 9c04c9c917154d33fde9bf2c663af06b0d702735 3246 dovecot_2.2.33.2-1ubuntu3.dsc
 e9a8478cde054af3738a851d44018b22248a7898 891276 dovecot_2.2.33.2-1ubuntu3.debian.tar.xz
 b0e5546f09fabddd1969eff95339595379fdf095 8616 dovecot_2.2.33.2-1ubuntu3_source.buildinfo
Checksums-Sha256:
 285d35749ae57ed54317761ff5a01eae5ec8e54c5f49462a4dede9312980d76b 3246 dovecot_2.2.33.2-1ubuntu3.dsc
 928d144f6a38493bab37a88d5886f65a55d6bd17e2becc171b67881b0960d762 891276 dovecot_2.2.33.2-1ubuntu3.debian.tar.xz
 c1c65275ed0818927513ec69d6d869fa4895c2a3cc899b093239609e18b4107f 8616 dovecot_2.2.33.2-1ubuntu3_source.buildinfo
Files:
 deef1ef0167d0c3ac092b5613b6f20c6 3246 mail optional dovecot_2.2.33.2-1ubuntu3.dsc
 0d9e25189b4aa4723394380f96ef7678 891276 mail optional dovecot_2.2.33.2-1ubuntu3.debian.tar.xz
 7bdebb9e93155cff1932649e65b07f89 8616 mail optional dovecot_2.2.33.2-1ubuntu3_source.buildinfo
Original-Maintainer: Dovecot Maintainers <jaldhar-dovecot at debian.org>

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJakDCuAAoJEGVp2FWnRL6TlmEQAKG+9as4tKhTdrAKfuj2+3bD
SXAoMG3iojY3tMcJGj+kNhosqVi7NVRlRIAxKSm7BWX3PI5menZx3xpk6H8wgI34
UQ66xr55xsFH98UoH1S2WJgBzSE+Nz3SnNCwHn5w6wTMEPKEI2eePeBReT2w7W+j
NM3UuX+lDAVaGDzi9chCNWBQe9hJ99HwDDXRhiSxfyZ1Kil4v9u4XXwq5geUqrKE
n0/OYDgG79UtKxC6AniiITencetU+uv1eaA5e1kKL6UKoqRkgxfkFDfcoGFLIEOn
eUskjA9LTE97WYCgLI0BKIXakqhsYjv3TrcGniUonZLxioU96NfYgTwcNq0wGrqh
jfIrCk0N/ojKNFYqWYJdDCq5SSa4nb6pbp06JLCW+PBchIfpg4JVXYuUbEacs5zd
IZrsy7CGbbmfHIdh/g6IFzEnYJTZAgC9ZsIjnme1AXIVXab1BQanG1K83y41Jxe3
TmjG780N3Sh+76ObzI+hx3uPwSv6dvwJUn/EEpSfIPzs5PFdShUQmgsjG3y0uaUs
8FCXBmR6GJijDfeGiSrAliAmjzsmFdsipsSinaHtUMwITVs0dfh4CeoSqK+TWbgL
ASIyjGTZ8a9utDuiS7n4Gm+i/S4AnfmFLdNvLlothgbJ8yMoGUsDtszeyXesyg7n
TpjdtE+stSgIhK0cgBvU
=O7Uu
-----END PGP SIGNATURE-----


More information about the Bionic-changes mailing list