[Backports-security-announce] Security update for dovecot
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Jaldhar H. Vyas uploaded new packages which fix the following problem:
DSA-1892-1
CVE-2009-2632, CVE-2009-3235
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot
For the etch-backports distribution the problem has been fixed in
version 1.0.15-2.3+lenny1~bpo40+1
For the lenny-backports distribution the problem has been fixed in
version 1.2.4-2~bpo50+1 (note this is because the 1.2.x series include an
entirely new sieve plugin.)
Upgrade instructions
- --------------------
If you don't use pinning
(http://backports.org/dokuwiki/doku.php?id=instructions) you have to
update the package manually via apt-get -t lenny-backports install
<packagename>.
We recommend to pin the backports repository to 200 so that new versions
of installed backports will be installed automatically.
Package: *
Pin: release a=lenny-backports
Pin-Priority: 200
- --
Jaldhar H. Vyas <jaldhar@debian.org>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkrE8TsACgkQ2kYOR+5txmqNKACePDe3O0woM7pqqywCFtU3niYN
91IAn3xMyO+WPK1lBNIV1MPDWVc9DOxd
=qCwl
-----END PGP SIGNATURE-----
Reply to: