Comment 18 for bug 24758

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Mon, 14 Nov 2005 21:06:47 +0100
From: Nico Golde <email address hidden>
To: Loic Minier <email address hidden>, <email address hidden>
Cc: <email address hidden>
Subject: Re: Bug#323027: IMPORTANT: fetchmail regression in 6.2.5-12sarge1

--IJpNTDwzlM2Ie8A6
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi,
* Loic Minier <email address hidden> [2005-11-14 20:56]:
> While preparing a fix for CVE-2005-3088 (#336096), the Debian bugs
> #323027 and #327893 were brought to my attention. It seems to me other
> quality fixes were included in the 6.2.5-12sarge1 version, basically
> including parts of the upstream "6.2.5.2" stable release and causing
> new bugs to appear; I believe this is far too much changes for a
> security upload.

What do you think exactly? The changes from 6.2.5.2 fixed=20
CVE-2005-2335, Steve Kemp prepared the fixed package.
But you are right it seems that some things are broken, for=20
example the apop support.

> I attach "fetchmail_6.2.5-12sarge1.diff", the interdiff between
> 6.2.5-12 and 6.2.5-12sarge1, for you to recheck you want to include it
> completely. My understanding is that the patch in
> "fetchmail_CAN-2005-2335.diff" would have been enough for sarge1.

yes

> Since I'm preparing sarge2, I propose I revert the changes of sarge1,
> except for "fetchmail_CAN-2005-2335.diff", and fix CVE-2005-3088 with
> the patch I've already sent you. I can also prepare a stable upload
> based on sarge2 with more fixes (possibly all) from the stable upstream
> release 6.2.5.4.
>=20
> Please let me know rapidly whether this suits you.

[...]=20
Ok with me.
Regards Nico
--=20
Nico Golde - JAB: <email address hidden> | GPG: 0x73647CFF
http://www.ngolde.de | http://www.muttng.org | http://grml.org
Forget about that mouse with 3/4/5 buttons -
gimme a keyboard with 103/104/105 keys!

--IJpNTDwzlM2Ie8A6
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDeO5XHYflSXNkfP8RAityAKCtNvc5wtNLGP9h72VV0KAMjb7c8QCdEIIs
YWJ9VejYWl9MkDwbw13Eaiw=
=FCgx
-----END PGP SIGNATURE-----

--IJpNTDwzlM2Ie8A6--