[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[Backports-security-announce] Security update for dovecot



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Jaldhar H. Vyas uploaded new packages which fix the following problem:

DSA-1892-1
CVE-2009-2632, CVE-2009-3235
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot

For the etch-backports distribution the problem has been fixed in
version 1.0.15-2.3+lenny1~bpo40+1

For the lenny-backports distribution the problem has been fixed in
version 1.2.4-2~bpo50+1 (note this is because the 1.2.x series include an 
entirely new sieve plugin.)

Upgrade instructions
- --------------------

If you don't use pinning
(http://backports.org/dokuwiki/doku.php?id=instructions) you have to
update the package manually via apt-get -t lenny-backports install
<packagename>.

We recommend to pin the backports repository to 200 so that new versions
of installed backports will be installed automatically.

 Package: *
 Pin: release a=lenny-backports
 Pin-Priority: 200


- -- 
Jaldhar H. Vyas <jaldhar@debian.org>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkrE8TsACgkQ2kYOR+5txmqNKACePDe3O0woM7pqqywCFtU3niYN
91IAn3xMyO+WPK1lBNIV1MPDWVc9DOxd
=qCwl
-----END PGP SIGNATURE-----

Reply to: