-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 20 Mar 2014 10:41:47 +0100 Source: postfixadmin Binary: postfixadmin Architecture: source all Version: 2.3.5-2+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Norman Messtorff <normes@normes.org> Changed-By: Gaudenz Steinlin <gaudenz@debian.org> Description: postfixadmin - Virtual mail hosting interface for Postfix Changes: postfixadmin (2.3.5-2+deb7u1) wheezy-security; urgency=high . * Non-maintainer upload * SECURITY: fix SQL injection in show_gen_status() This is only exploitable by authenticated users able to create new aliases. Upstream commit: http://sourceforge.net/p/postfixadmin/code/1650 Checksums-Sha1: 4b6eb5f5b5bf77e7ca746c99b4e78e08e98d1ada 1920 postfixadmin_2.3.5-2+deb7u1.dsc d1993ebb5a6c792efc4dfa297e856073474ffce8 1596672 postfixadmin_2.3.5.orig.tar.gz 908addb9135b2c77713d9d4c97fc1aab24e494cd 9747 postfixadmin_2.3.5-2+deb7u1.debian.tar.gz ed35a5a410cf5cbe91f8d18399b1849ff310f0e1 1000924 postfixadmin_2.3.5-2+deb7u1_all.deb Checksums-Sha256: 21b80bdbdb8e37050619817373c353d2f6070f40aabc48b63934df8a1b38dda6 1920 postfixadmin_2.3.5-2+deb7u1.dsc ba53e8c5feb8566bf88525b2147c83103e01c9282d17294638a0db08cc1b42c8 1596672 postfixadmin_2.3.5.orig.tar.gz 1b02fcc51c4eb93a01288ea47ec699009e114c40b885c58d8c1308d6ce5797bc 9747 postfixadmin_2.3.5-2+deb7u1.debian.tar.gz 8c3c182b2bf78afeb8cb6fc392fe56f01b8f107c18b356866600283e6905dbb9 1000924 postfixadmin_2.3.5-2+deb7u1_all.deb Files: 556c32870cc99a8a9c362f5778622444 1920 admin optional postfixadmin_2.3.5-2+deb7u1.dsc 9a72ed8d827fa2c7f641001f2aa87814 1596672 admin optional postfixadmin_2.3.5.orig.tar.gz 457ef3771a86b017c9ef3039754a198d 9747 admin optional postfixadmin_2.3.5-2+deb7u1.debian.tar.gz 774f7f108e8136de417e155f1b55229e 1000924 admin optional postfixadmin_2.3.5-2+deb7u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBUzLqBM3PKyWkzVd5AQpcsxAAj2bThPc1pATo9UUMPobMD6Cwwz8mK8+4 8GPJ8fnxKmG1rqMoxfIpH/U031RIXU1k18dHlW5Xp+XBu75tWrARmWDFujTc8V5d 6DfM6mWmbnQaQ3/SDTbOY7OSgSBsSPoKIUO1FQ8C4b78m9GWR3wp23P1JKA04N91 SlGels2IE061YnE9KG/TZTHpQE15IHMnFoiUzPL4eHo0ipQv9P6dbvY4TxsJhdgk Z/pQrRuCaeOibv961tvG0z601bTWZ/EBRbdGOdPU4IQ7/z3jeCQmTvxwRYd6nzLC Y8Qj0lb8epMmzBbOQbJ5YGyujYpy0jOwJO7niHA8TEq4GbOw9UTp9e+v/xebragd vJb5F8D1tisSCQoKSWEsOMOJGDCvjjWcW99MZ4mf52QPpL17syn0wGSI1ZB7NWt4 0wOjrj3jkgxlLVKTVybQBooYlBzCj52QgoU0Zi78OkygH1D++a4iQrPrYBFzaOT3 HSj8jYlH0w3EdZU9Vz7b/IQCgZhzlfrB4LldkHbqGlAwAL0tdkFEnGEKi4evRXD8 G2AmXw/IjZbx9AD7Dei1EuVmu4w1jRHGQGI6wlGq17l1vloxIEoeWV/XfJFIjSgM XSBBXM7MHWFGNrMvq77Kbr4dfeEmBd64d9w16Nms09eZWbvipLr1M0Dwj+OwnMiC 3L3eBl9AML4= =Yjms -----END PGP SIGNATURE-----