Fedora Legacy Test Update Notification: cyrus-imapd

Marc Deslauriers marcdeslauriers at videotron.ca
Thu Mar 16 01:31:43 UTC 2006


---------------------------------------------------------------------
Fedora Legacy Test Update Notification
FEDORALEGACY-2006-156290
Bugzilla https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=156290
2006-03-15
---------------------------------------------------------------------

Name        : cyrus-imapd
Versions    : fc2: cyrus-imapd-2.2.12-1.1.fc2.1.legacy
Summary     : A high-performance mail server with IMAP, POP3, NNTP
              and SIEVE support.
Description :
The cyrus-imapd package contains the core of the Cyrus IMAP server.
It is a scaleable enterprise mail system designed for use from
small to large enterprise environments using standards-based
internet mail technologies.

---------------------------------------------------------------------
Update Information:

Updated cyrus-imapd packages that fix several buffer overflow security
issues are now available.

The cyrus-imapd package contains the core of the Cyrus IMAP server.

Several buffer overflow bugs were found in cyrus-imapd. It is possible
that an authenticated malicious user could cause the imap server to
crash. Additionally, a peer news admin could potentially execute
arbitrary code on the imap server when news is received using the
fetchnews command. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2005-0546 to this issue.

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain cyrus-imapd version 2.2.12 to correct these issues.

---------------------------------------------------------------------
Changelogs

fc2:
* Mon Mar 06 2006 Marc Deslauriers <marcdeslauriers at videotron.ca>
2.2.12-1.1.fc2.1.legacy
- Update to 2.2.12 to fix CVE-2005-0546. The only difference between
  2.2.10 and 2.2.12 was the security fix, so upgrading is the
  equivalent of backporting the security fix.

---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedoralegacy.org/
(sha1sums)

fc2:
869a5d94e05156e2bdcff36242fd25b2c0e1c6d1
fedora/2/updates-testing/i386/cyrus-imapd-2.2.12-1.1.fc2.1.legacy.i386.rpm
b3bfaca68420697544395c17dbf2cefb5eabcf8f
fedora/2/updates-testing/i386/cyrus-imapd-devel-2.2.12-1.1.fc2.1.legacy.i386.rpm
0a8652c25f5d608811b64c634191845b6dcd672a
fedora/2/updates-testing/i386/cyrus-imapd-murder-2.2.12-1.1.fc2.1.legacy.i386.rpm
d7cfe6d91b0aa23b189949bf516e94479eefd8ef
fedora/2/updates-testing/i386/cyrus-imapd-nntp-2.2.12-1.1.fc2.1.legacy.i386.rpm
03b23f099fd26fa8421bf90f4542ff4e56226d36
fedora/2/updates-testing/i386/cyrus-imapd-utils-2.2.12-1.1.fc2.1.legacy.i386.rpm
1d1f935c0d88f209321ebb9ae679af9a0ff23e42
fedora/2/updates-testing/i386/perl-Cyrus-2.2.12-1.1.fc2.1.legacy.i386.rpm
de27bfdc5d7e2a2c5268d769ef0842aba85bfed5
fedora/2/updates-testing/SRPMS/cyrus-imapd-2.2.12-1.1.fc2.1.legacy.src.rpm

---------------------------------------------------------------------

Please test and comment in bugzilla.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 191 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/fedora-legacy-list/attachments/20060315/c06ad04d/attachment.sig>


More information about the fedora-legacy-list mailing list