We believe that the bug you reported is fixed in the latest version of
cyrus21-imapd, which is due to be installed in the Debian FTP archive:
cyrus21-admin_2.1.16-11_all.deb
to pool/main/c/cyrus21-imapd/cyrus21-admin_2.1.16-11_all.deb
cyrus21-clients_2.1.16-11_i386.deb
to pool/main/c/cyrus21-imapd/cyrus21-clients_2.1.16-11_i386.deb
cyrus21-common_2.1.16-11_i386.deb
to pool/main/c/cyrus21-imapd/cyrus21-common_2.1.16-11_i386.deb
cyrus21-dev_2.1.16-11_i386.deb
to pool/main/c/cyrus21-imapd/cyrus21-dev_2.1.16-11_i386.deb
cyrus21-doc_2.1.16-11_all.deb
to pool/main/c/cyrus21-imapd/cyrus21-doc_2.1.16-11_all.deb
cyrus21-imapd_2.1.16-11.diff.gz
to pool/main/c/cyrus21-imapd/cyrus21-imapd_2.1.16-11.diff.gz
cyrus21-imapd_2.1.16-11.dsc
to pool/main/c/cyrus21-imapd/cyrus21-imapd_2.1.16-11.dsc
cyrus21-imapd_2.1.16-11_i386.deb
to pool/main/c/cyrus21-imapd/cyrus21-imapd_2.1.16-11_i386.deb
cyrus21-murder_2.1.16-11_i386.deb
to pool/main/c/cyrus21-imapd/cyrus21-murder_2.1.16-11_i386.deb
cyrus21-pop3d_2.1.16-11_i386.deb
to pool/main/c/cyrus21-imapd/cyrus21-pop3d_2.1.16-11_i386.deb
libcyrus-imap-perl21_2.1.16-11_i386.deb
to pool/main/c/cyrus21-imapd/libcyrus-imap-perl21_2.1.16-11_i386.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to <email address hidden>,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Henrique de Moraes Holschuh <email address hidden> (supplier of updated cyrus21-imapd package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing <email address hidden>)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Tue, 23 Nov 2004 10:43:11 -0200
Source: cyrus21-imapd
Binary: cyrus21-doc cyrus21-admin cyrus21-murder cyrus21-common cyrus21-imapd cyrus21-clients cyrus21-dev cyrus21-pop3d libcyrus-imap-perl21
Architecture: source i386 all
Version: 2.1.16-11
Distribution: unstable
Urgency: high
Maintainer: Henrique de Moraes Holschuh <email address hidden>
Changed-By: Henrique de Moraes Holschuh <email address hidden>
Description:
cyrus21-admin - Cyrus mail system (administration tool)
cyrus21-clients - Cyrus mail system (test clients)
cyrus21-common - Cyrus mail system (common files)
cyrus21-dev - Cyrus mail system (developer files)
cyrus21-doc - Cyrus mail system (documentation files)
cyrus21-imapd - Cyrus mail system (IMAP support)
cyrus21-murder - Cyrus mail system (proxies and aggregator)
cyrus21-pop3d - Cyrus mail system (POP3 support)
libcyrus-imap-perl21 - Interface to Cyrus imap client imclient library
Closes: 231068 277072 282619
Changes:
cyrus21-imapd (2.1.16-11) unstable; urgency=high
.
* SECURITY FIX: Exploitable remotely. Could cause root compromise.
CAN-2004-1012, CAN-2004-1013. Backport of upstream 2.2.x fixes to
2.1.16 by David Carter (closes: #282619)
* Possible security fix: don't assume long lines have a null in them. from
Philip Chambers <email address hidden>. Backported from 2.2.9
* Change suggested DEB_BUILD_OPTIONS for debugging in README.Debian.debug
* Add note about really meaning it when I tell people to pay attention to
their new SASLv2 setup in UPGRADE.Debian (closes: #277072)
* Always remove all dpkg-statusoverride entries, even if the user request
that the spool directories not be removed (closes: #231068)
Files:
3c7767779d59dc3fea0226ce09a5f61b 1024 mail extra cyrus21-imapd_2.1.16-11.dsc
e8ccabd7dbb42bbeec8dfdee617253d4 252751 mail extra cyrus21-imapd_2.1.16-11.diff.gz
f9116b12a639db7fedb38a0423ccbcc0 208676 mail extra cyrus21-doc_2.1.16-11_all.deb
99babf31032e1d1f9c548745704da4f3 89240 mail extra cyrus21-admin_2.1.16-11_all.deb
670084d140329e4b52e893bb819873dd 1992594 mail extra cyrus21-common_2.1.16-11_i386.deb
8975fc83c7a0033d9a154f442d9e4782 570692 mail extra cyrus21-imapd_2.1.16-11_i386.deb
c2ef5b0b190bf998183ec45887929105 87892 mail extra cyrus21-pop3d_2.1.16-11_i386.deb
400e07ba51092b57754ee1b90729c6fc 503678 mail extra cyrus21-murder_2.1.16-11_i386.deb
cba017966cf3bc32103aae3c0421a4db 106038 mail extra cyrus21-clients_2.1.16-11_i386.deb
3978a093b415b574e1c333cd1cb372a2 244152 devel extra cyrus21-dev_2.1.16-11_i386.deb
f04cc26a1d862619c82ee4e55215cafe 136820 perl extra libcyrus-imap-perl21_2.1.16-11_i386.deb
Source: cyrus21-imapd
Source-Version: 2.1.16-11
We believe that the bug you reported is fixed in the latest version of
cyrus21-imapd, which is due to be installed in the Debian FTP archive:
cyrus21- admin_2. 1.16-11_ all.deb c/cyrus21- imapd/cyrus21- admin_2. 1.16-11_ all.deb clients_ 2.1.16- 11_i386. deb c/cyrus21- imapd/cyrus21- clients_ 2.1.16- 11_i386. deb common_ 2.1.16- 11_i386. deb c/cyrus21- imapd/cyrus21- common_ 2.1.16- 11_i386. deb dev_2.1. 16-11_i386. deb c/cyrus21- imapd/cyrus21- dev_2.1. 16-11_i386. deb doc_2.1. 16-11_all. deb c/cyrus21- imapd/cyrus21- doc_2.1. 16-11_all. deb imapd_2. 1.16-11. diff.gz c/cyrus21- imapd/cyrus21- imapd_2. 1.16-11. diff.gz imapd_2. 1.16-11. dsc c/cyrus21- imapd/cyrus21- imapd_2. 1.16-11. dsc imapd_2. 1.16-11_ i386.deb c/cyrus21- imapd/cyrus21- imapd_2. 1.16-11_ i386.deb murder_ 2.1.16- 11_i386. deb c/cyrus21- imapd/cyrus21- murder_ 2.1.16- 11_i386. deb pop3d_2. 1.16-11_ i386.deb c/cyrus21- imapd/cyrus21- pop3d_2. 1.16-11_ i386.deb imap-perl21_ 2.1.16- 11_i386. deb c/cyrus21- imapd/libcyrus- imap-perl21_ 2.1.16- 11_i386. deb
to pool/main/
cyrus21-
to pool/main/
cyrus21-
to pool/main/
cyrus21-
to pool/main/
cyrus21-
to pool/main/
cyrus21-
to pool/main/
cyrus21-
to pool/main/
cyrus21-
to pool/main/
cyrus21-
to pool/main/
cyrus21-
to pool/main/
libcyrus-
to pool/main/
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to <email address hidden>,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Henrique de Moraes Holschuh <email address hidden> (supplier of updated cyrus21-imapd package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing <email address hidden>)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7 imap-perl21 imap-perl21 - Interface to Cyrus imap client imclient library 3fea0226ce09a5f 61b 1024 mail extra cyrus21- imapd_2. 1.16-11. dsc beec8dfdee61725 3d4 252751 mail extra cyrus21- imapd_2. 1.16-11. diff.gz 7fedb38a0423ccb cc0 208676 mail extra cyrus21- doc_2.1. 16-11_all. deb 1f9c548745704da 4f3 89240 mail extra cyrus21- admin_2. 1.16-11_ all.deb 4b52e893bb81987 3dd 1992594 mail extra cyrus21- common_ 2.1.16- 11_i386. deb 3d9a154f442d9e4 782 570692 mail extra cyrus21- imapd_2. 1.16-11_ i386.deb 98183ec45887929 105 87892 mail extra cyrus21- pop3d_2. 1.16-11_ i386.deb 57754ee1b90729c 6fc 503678 mail extra cyrus21- murder_ 2.1.16- 11_i386. deb 32103aae3c0421a 4db 106038 mail extra cyrus21- clients_ 2.1.16- 11_i386. deb 74e1c333cd1cb37 2a2 244152 devel extra cyrus21- dev_2.1. 16-11_i386. deb 19c82ee4e55215c afe 136820 perl extra libcyrus- imap-perl21_ 2.1.16- 11_i386. deb
Date: Tue, 23 Nov 2004 10:43:11 -0200
Source: cyrus21-imapd
Binary: cyrus21-doc cyrus21-admin cyrus21-murder cyrus21-common cyrus21-imapd cyrus21-clients cyrus21-dev cyrus21-pop3d libcyrus-
Architecture: source i386 all
Version: 2.1.16-11
Distribution: unstable
Urgency: high
Maintainer: Henrique de Moraes Holschuh <email address hidden>
Changed-By: Henrique de Moraes Holschuh <email address hidden>
Description:
cyrus21-admin - Cyrus mail system (administration tool)
cyrus21-clients - Cyrus mail system (test clients)
cyrus21-common - Cyrus mail system (common files)
cyrus21-dev - Cyrus mail system (developer files)
cyrus21-doc - Cyrus mail system (documentation files)
cyrus21-imapd - Cyrus mail system (IMAP support)
cyrus21-murder - Cyrus mail system (proxies and aggregator)
cyrus21-pop3d - Cyrus mail system (POP3 support)
libcyrus-
Closes: 231068 277072 282619
Changes:
cyrus21-imapd (2.1.16-11) unstable; urgency=high
.
* SECURITY FIX: Exploitable remotely. Could cause root compromise.
CAN-2004-1012, CAN-2004-1013. Backport of upstream 2.2.x fixes to
2.1.16 by David Carter (closes: #282619)
* Possible security fix: don't assume long lines have a null in them. from
Philip Chambers <email address hidden>. Backported from 2.2.9
* Change suggested DEB_BUILD_OPTIONS for debugging in README.Debian.debug
* Add note about really meaning it when I tell people to pay attention to
their new SASLv2 setup in UPGRADE.Debian (closes: #277072)
* Always remove all dpkg-statusoverride entries, even if the user request
that the spool directories not be removed (closes: #231068)
Files:
3c7767779d59dc
e8ccabd7dbb42b
f9116b12a639db
99babf31032e1d
670084d140329e
8975fc83c7a003
c2ef5b0b190bf9
400e07ba51092b
cba017966cf3bc
3978a093b415b5
f04cc26a1d8626
-----BEGIN PGP SIGNATURE-----
ePxzbD+ MRAlEtAJ9XPLY2v OXd37TB0ivSHGPD oHA5EwCfW0eo xbIs7DRQ=
Version: GnuPG v1.2.5 (GNU/Linux)
iD8DBQFBozKP7iX
bmtcaKRUfPB0mPY
=A80r
-----END PGP SIGNATURE-----