[ubuntu/bionic-proposed] dovecot 1:2.2.33.2-1ubuntu4 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Mon Mar 5 12:49:21 UTC 2018


dovecot (1:2.2.33.2-1ubuntu4) bionic; urgency=medium

  * SECURITY UPDATE: rfc822_parse_domain Information Leak Vulnerability
    - debian/patches/CVE-2017-14461/*.patch: upstream parsing fixes.
    - CVE-2017-14461
  * SECURITY UPDATE: TLS SNI config lookups DoS
    - debian/patches/CVE-2017-15130/*.patch: upstream config filtering fix.
    - CVE-2017-15130

Date: Mon, 26 Feb 2018 12:34:24 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/dovecot/1:2.2.33.2-1ubuntu4
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 26 Feb 2018 12:34:24 -0500
Source: dovecot
Binary: dovecot-core dovecot-dev dovecot-imapd dovecot-pop3d dovecot-lmtpd dovecot-managesieved dovecot-pgsql dovecot-mysql dovecot-sqlite dovecot-ldap dovecot-gssapi dovecot-sieve dovecot-solr mail-stack-delivery
Architecture: source
Version: 1:2.2.33.2-1ubuntu4
Distribution: bionic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
 dovecot-core - secure POP3/IMAP server - core files
 dovecot-dev - secure POP3/IMAP server - header files
 dovecot-gssapi - secure POP3/IMAP server - GSSAPI support
 dovecot-imapd - secure POP3/IMAP server - IMAP daemon
 dovecot-ldap - secure POP3/IMAP server - LDAP support
 dovecot-lmtpd - secure POP3/IMAP server - LMTP server
 dovecot-managesieved - secure POP3/IMAP server - ManageSieve server
 dovecot-mysql - secure POP3/IMAP server - MySQL support
 dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support
 dovecot-pop3d - secure POP3/IMAP server - POP3 daemon
 dovecot-sieve - secure POP3/IMAP server - Sieve filters support
 dovecot-solr - secure POP3/IMAP server - Solr support
 dovecot-sqlite - secure POP3/IMAP server - SQLite support
 mail-stack-delivery - mail server delivery agent stack provided by Ubuntu server team
Changes:
 dovecot (1:2.2.33.2-1ubuntu4) bionic; urgency=medium
 .
   * SECURITY UPDATE: rfc822_parse_domain Information Leak Vulnerability
     - debian/patches/CVE-2017-14461/*.patch: upstream parsing fixes.
     - CVE-2017-14461
   * SECURITY UPDATE: TLS SNI config lookups DoS
     - debian/patches/CVE-2017-15130/*.patch: upstream config filtering fix.
     - CVE-2017-15130
Checksums-Sha1:
 039a129ce4bf95a4e8287704f80de8303d41881a 3246 dovecot_2.2.33.2-1ubuntu4.dsc
 e5475866af3951bc23a50626ad6b38d92a45691f 900956 dovecot_2.2.33.2-1ubuntu4.debian.tar.xz
 09745ecf70f35d20a236d96bdb9809475cb0f38c 8616 dovecot_2.2.33.2-1ubuntu4_source.buildinfo
Checksums-Sha256:
 b6301d552bdded8ecdf8c25252203c864d75804bef6187efa05789939ef1a13b 3246 dovecot_2.2.33.2-1ubuntu4.dsc
 a1ba40a4b94714910511f0e327d91f31fefeedfc42d62bd9dbc6e615226eac0b 900956 dovecot_2.2.33.2-1ubuntu4.debian.tar.xz
 e55e2c05a23568d19c816a841a6afd9b1af72815b8ae3f6db519390a7fe90bfb 8616 dovecot_2.2.33.2-1ubuntu4_source.buildinfo
Files:
 b0ee363fdb961b96b806b8e0fb1b0489 3246 mail optional dovecot_2.2.33.2-1ubuntu4.dsc
 1a93b0bccc2f4242579da0806f4631e5 900956 mail optional dovecot_2.2.33.2-1ubuntu4.debian.tar.xz
 88574d717d18699899538409f9dac9b9 8616 mail optional dovecot_2.2.33.2-1ubuntu4_source.buildinfo
Original-Maintainer: Dovecot Maintainers <jaldhar-dovecot at debian.org>

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJanTwtAAoJEGVp2FWnRL6TFLwP/RZ2VXyJxox1nHTYnvOUViTR
OiebrjNT5Z+XoC9eG9HE1LmqS4HM8oXlfOuwh45uinffuwIJGoeaqWVHXrme+ifB
xut9Z2ksInb17j79ouUW/8PhUwFvwf8Pv/IV5Tf+hwADav5lXDBj26yhOvgKw88l
sJw3RbI2VNv8AjRFYQUFOECzr17cYmHdji6fbI4XK3e4pxCyx8bmaOgPaz7OXlpi
268qz2N/fUuvtKRRL68KFg2qHPWXIayViW3mPzsZIz8ZlJF6ET6F6BTyVW46Jd8s
jn0Tm8AwjP88v8sGr2XxaiCj3Ch4+3daX0eLZo8dAdHOVudCslGCBXlzswlg2wi0
Ltgo48hebr9+M8/9lTgzXg0hVTDASnIl07Se+r4TN1rLUIpMBvm/IPo5bXbakX12
rh1vCRvk54xDESsFeswO++8fs1QUBGJTKw077y7Kf8cUw2AAVdgFrCp7bF7noYLZ
D0cVUJyZ/xEt4XkwJ4WzLeppds/C5egqcs3CgJczGrIQ8wATQEKrX1w0yruUyDOt
O3hOVN6SfPDPuyqp5OChiRn/YKdKMmmXDruT/Y1f3L20mBfTEDIAoOXISWeymdH1
m07jCpjGT86KGIvRPlQjDYEWTgL7skiERcwdgZk+Q3dKRAtZsfmOYkN2r5q5XFg/
tekYYSNK6K18KJESGyKY
=Kn7s
-----END PGP SIGNATURE-----


More information about the Bionic-changes mailing list