-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 15 Nov 2005 10:01:11 +0100 Source: fetchmail Binary: fetchmailconf fetchmail-ssl fetchmail Architecture: source powerpc all Version: 6.2.5-12sarge3 Distribution: stable-security Urgency: high Maintainer: Martin Schulze <joey@debian.org> Changed-By: Martin Schulze <joey@infodrom.org> Description: fetchmail - SSL enabled POP3, APOP, IMAP mail gatherer/forwarder fetchmail-ssl - SSL enabled POP3, APOP, IMAP mail gatherer/forwarder fetchmailconf - fetchmail configurator Changes: fetchmail (6.2.5-12sarge3) stable-security; urgency=high . * Non-maintainer upload by the Security Team * Completely reworked the security update(s), which removes a regression and other pieces that accidentally creeped in with the last update * Applied patch by Ludwig Nussel to fix arbitrary code execution [pop3.c, CAN-2005-2335] * Adjusted the umask when opening the config file to prevent information disclosure [fetchmailconf, CVE-2005-3088] Files: 6dd801f3e8877367a3000f1facc0126d 650 mail optional fetchmail_6.2.5-12sarge3.dsc 4d0139fa9e5454ab9fdc6f1eb48283e0 150051 mail optional fetchmail_6.2.5-12sarge3.diff.gz 04f2e561760abcd1c66aeec0c0b117f6 101250 mail optional fetchmailconf_6.2.5-12sarge3_all.deb 3fbfce00d6a72c377a86e0cb95824705 42164 mail optional fetchmail-ssl_6.2.5-12sarge3_all.deb 6437a64037de6c104f815db8a2e3de82 556144 mail optional fetchmail_6.2.5-12sarge3_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) iD8DBQFDeawpW5ql+IAeqTIRAtLCAJ9TTKOCiut4VxTQYRk9qbsmnNfPsgCeOhpr NzCRs6pqq/5ulOKbYrJkq3w= =2rxd -----END PGP SIGNATURE----- Accepted: fetchmail-ssl_6.2.5-12sarge3_all.deb to pool/main/f/fetchmail/fetchmail-ssl_6.2.5-12sarge3_all.deb fetchmail_6.2.5-12sarge3.diff.gz to pool/main/f/fetchmail/fetchmail_6.2.5-12sarge3.diff.gz fetchmail_6.2.5-12sarge3.dsc to pool/main/f/fetchmail/fetchmail_6.2.5-12sarge3.dsc fetchmail_6.2.5-12sarge3_powerpc.deb to pool/main/f/fetchmail/fetchmail_6.2.5-12sarge3_powerpc.deb fetchmailconf_6.2.5-12sarge3_all.deb to pool/main/f/fetchmail/fetchmailconf_6.2.5-12sarge3_all.deb