-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 30 Apr 2019 21:26:28 EEST Source: dovecot Architecture: source Version: 1:2.3.4.1-5 Distribution: unstable Urgency: medium Maintainer: Dovecot Maintainers <dovecot@packages.debian.org> Changed-By: Apollon Oikonomopoulos <apoikos@debian.org> Closes: 928235 Changes: dovecot (1:2.3.4.1-5) unstable; urgency=medium . * [bd00402] Fix CVE-2019-11494 and CVE-2019-11499 (Closes: #928235) - submission-login: fix null pointer dereference when client disconnects during authentication (CVE-2019-11494) - submission-login: fix assert-crash when receiving an invalid authentication message over TLS (CVE-2019-11499) Checksums-Sha256: 45fa97e83e60abaf567518a061fc8b30b7cca7a07af475cd7316dc8e449110a5 3590 dovecot_2.3.4.1-5.dsc 51d4699c3631ca2cb7bcae5ddb9a945b4cd927879ebc4a0c3e9fdc7f4dab425e 533900 dovecot_2.3.4.1-5.debian.tar.xz a89ddd4ab25b58a67ee4975a8b6f9316bc656f5cabd725ab27d7317bbf372f50 9024 dovecot_2.3.4.1-5_source.buildinfo d244ae94e316e69a1c2fb272cadd71a5c87b4dfa88edfcc511eceb1dd2252c5d 1286 dovecot_2.3.4.1.orig.tar.gz.asc Checksums-Sha1: 5c4c28e1a5440ae449f74f5889e6d81098cd4f2f 3590 dovecot_2.3.4.1-5.dsc d84107710a4aa1e948e6ea212c086fa0b20bf5b2 533900 dovecot_2.3.4.1-5.debian.tar.xz 1722fc76dfbf12976487ecc658d46b841a8978bd 9024 dovecot_2.3.4.1-5_source.buildinfo cf6a7d63be252c98b0aeed62fb1e8cea558fd2a1 1286 dovecot_2.3.4.1.orig.tar.gz.asc Files: 320c2f1e20bebdee323da34e0e00ee26 3590 mail optional dovecot_2.3.4.1-5.dsc d0a6314f3421f98c319fc36e722beed1 533900 mail optional dovecot_2.3.4.1-5.debian.tar.xz 66fb79cb18868b42061d768953d89eff 9024 mail optional dovecot_2.3.4.1-5_source.buildinfo 8c93e4114a2edfd50e881bc0be06e82a 1286 - - dovecot_2.3.4.1.orig.tar.gz.asc -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEPgL9ZlYpWVIRC6uZ9RsYxyAkgiQFAlzIk20ACgkQ9RsYxyAk giQydhAAsxAm+13OJqYqBGacS3AD9KeGys46uTMxRBazynuE3SyP+QqXtjtyT5z8 AyUImVKp7Xc/GpHi5qmNqTFtPeNkpHHWNy6UBIRUjFZZbU4ed3QfV+KQwNgyJqrV /RUsvOQ/lqkwf7Umdgr77Y2lHUwNy+tlKVIa2XdzEuW8rTb76PVFFYVxn0Ao9vH0 KHB+ew2rjNKz8EmMSJWc4EfW+4OUY4b9Rkfb9f30tP29ordEXsFoD2A8Y9Y5844a YW1v80NVyLAmD+2eQJhGgc0WWgzYCnoVXaH2MSeVswYrSz6SU3aPnrS6Jg2r+hvq 8dHU3HJftg306RFZk5GStG4jk407xE3MQxOo6wC15qZCECdNsTH+nUnmF8i2nM/R 5jOrlOEWC9ZBKMX2o5Nzby81lJmnv3UgBrcAReliidCmnM4EL48jC6zqXS91k7vB vG2POoVQiBU7l5VBo3J4jJ2TsQ64wdzKfCWqX0epq/l+WKWdbntWdlPHyVizURYL WK63lw3QltM3MOG/SFaLYr3BoJBz902VImG4eIpjrSpfLDPiPJgaHxUFSqZBuNzD Qa0seWL1JoHEEmj4BzPTcWtmXcdRSOoX0IGX497WxFctlli149DHdYCkVFXjgbYg JBy6/isrcTTWOSRxrxaHvC2w1TEoSJUi4eGhV04MMfqYFtubvoo= =yxHS -----END PGP SIGNATURE-----