[ubuntu/precise] dovecot 1:2.0.15-1ubuntu5 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Thu Dec 8 19:50:20 UTC 2011


dovecot (1:2.0.15-1ubuntu5) precise; urgency=low

  * SECURITY UPDATE: Incorrect cert Common Name verification when proxying
    - debian/patches/CVE-2011-4318.patch: correctly validate Common Name
      when a hostname is specified in src/login-common/{login-proxy.c,
      ssl-proxy.*,ssl-proxy-openssl.c}.
    - CVE-2011-4318

Date: Thu, 08 Dec 2011 14:34:36 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/precise/+source/dovecot/1:2.0.15-1ubuntu5
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 08 Dec 2011 14:34:36 -0500
Source: dovecot
Binary: dovecot-common dovecot-core dovecot-dev dovecot-imapd dovecot-pop3d dovecot-lmtpd dovecot-managesieved dovecot-pgsql dovecot-mysql dovecot-sqlite dovecot-ldap dovecot-gssapi dovecot-sieve dovecot-solr dovecot-dbg mail-stack-delivery dovecot-postfix
Architecture: source
Version: 1:2.0.15-1ubuntu5
Distribution: precise
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 dovecot-common - Transitional package for dovecot
 dovecot-core - secure mail server that supports mbox, maildir, dbox and mdbox ma
 dovecot-dbg - debug symbols for Dovecot
 dovecot-dev - header files for the dovecot mail server
 dovecot-gssapi - GSSAPI authentication support for Dovecot
 dovecot-imapd - secure IMAP server that supports mbox, maildir, dbox and mdbox ma
 dovecot-ldap - LDAP support for Dovecot
 dovecot-lmtpd - secure LMTP server for Dovecot
 dovecot-managesieved - secure ManageSieve server for Dovecot
 dovecot-mysql - MySQL support for Dovecot
 dovecot-pgsql - PostgreSQL support for Dovecot
 dovecot-pop3d - secure POP3 server that supports mbox, maildir, dbox and mdbox ma
 dovecot-postfix - mail server delivery agent stack provided by Ubuntu server team
 dovecot-sieve - sieve filters support for Dovecot
 dovecot-solr - Solr full text search support for Dovecot
 dovecot-sqlite - SQLite support for Dovecot
 mail-stack-delivery - mail server delivery agent stack provided by Ubuntu server team
Changes: 
 dovecot (1:2.0.15-1ubuntu5) precise; urgency=low
 .
   * SECURITY UPDATE: Incorrect cert Common Name verification when proxying
     - debian/patches/CVE-2011-4318.patch: correctly validate Common Name
       when a hostname is specified in src/login-common/{login-proxy.c,
       ssl-proxy.*,ssl-proxy-openssl.c}.
     - CVE-2011-4318
Checksums-Sha1: 
 87c2b5f9f445f5472428277682342db531137e97 3151 dovecot_2.0.15-1ubuntu5.dsc
 3d9cfe413aef960ee4e72b90c8f8ecf1f21b297c 1007728 dovecot_2.0.15-1ubuntu5.debian.tar.gz
Checksums-Sha256: 
 b5bd17b2efed008adcf442dcca11ee1d7ceb0a40f52428ba660d09393feb6b8d 3151 dovecot_2.0.15-1ubuntu5.dsc
 ad3174151819deef97731c600097f238d882402218030564e725bb825e346015 1007728 dovecot_2.0.15-1ubuntu5.debian.tar.gz
Files: 
 2c198b2bf23166d0939d1768e5b6c1d2 3151 mail optional dovecot_2.0.15-1ubuntu5.dsc
 e9d95c43bdc5c670a123c7583e51f5cf 1007728 mail optional dovecot_2.0.15-1ubuntu5.debian.tar.gz
Original-Maintainer: Dovecot Maintainers <jaldhar-dovecot at debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCgAGBQJO4RPAAAoJEGVp2FWnRL6TfQwQALsg6TjohjnmVOWVHBN9NF9I
q8dKsf0GulLxQqTVVmtD+n29c5GzrRVnJKaJ9E25vmDElrRxeeSYxUV20YBgjXFe
LCkM4ZIUecgOCG610T3GBwApcPKrNY/0+PbJG/eut1s3+d97lXQrcOB4A4MSMiw4
5sqGUt//SdYsvFRQ21hnZudKcRH19T6Z8UcZZFz7v3yNWpcM0BpiovNKAauevBsA
x4FamklmmDzOalR0NlUOjK7fjHzMzPtjZ8yjffW1NR2q6i9JaoJgXBUtoxBwChOx
FFq9EV1q/S+/PehheCt/2xirDE56RC76xA/KqSijUumRPivtMo1cND7F6RyhHNqg
7InE6mRw7efXVEovQBkjZDnup65NR0gQSuWzYhf6tgS9C2SY4EQZUB5/l8W/sFng
EZtjwTU2dupqm92HNEUyFyRXPHRPeBvbgj9JVd3OsWFUl9WRObWslczDsSW716jn
Z4+3gcVMJPrQMNARDtFm4q3O1Q2O8CBIy7eyfS9XqZGqbyHIQZJ2yvxaqxMuNrnO
Ic78S4HijhdJ/xu21dNQe1VxMPnAdRmwI9XZXNUs6vGivUf/HIVH7BCv+QKGcf4y
324owTULvuM/BLpJ1f5JoWvL15vrVP676kQgKruEsRtpz04v/d5zClS33HGskWpG
5onFQ1mtBxtD4vqBUqNa
=sVAW
-----END PGP SIGNATURE-----


More information about the Precise-changes mailing list