-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 02 Mar 2018 19:59:01 +0200 Source: dovecot Binary: dovecot-core dovecot-dev dovecot-imapd dovecot-pop3d dovecot-lmtpd dovecot-managesieved dovecot-pgsql dovecot-mysql dovecot-sqlite dovecot-ldap dovecot-gssapi dovecot-sieve dovecot-solr dovecot-lucene Architecture: source amd64 Version: 1:2.2.34-2~bpo9+1 Distribution: stretch-backports Urgency: high Maintainer: Dovecot Maintainers <jaldhar-dovecot@debian.org> Changed-By: Apollon Oikonomopoulos <apoikos@debian.org> Description: dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-lucene - secure POP3/IMAP server - Lucene support dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support Closes: 888432 891819 891820 Changes: dovecot (1:2.2.34-2~bpo9+1) stretch-backports; urgency=medium . * Rebuild for stretch-backports. . dovecot (1:2.2.34-2) unstable; urgency=high . * [868dc65] Update pigeonhole to 0.4.22 * Set urgency to high due to the security fixes in 2.2.34-1 . dovecot (1:2.2.34-1) unstable; urgency=medium . * [f53dc9a] New upstream version 2.2.34 Fixes the following security issues: + CVE-2017-15130: TLS SNI config lookups may lead to excessive memory usage (Closes: #891820) + CVE-2017-14461: rfc822_parse_domain information leak vulnerability (Closes: #891819) + CVE-2017-15132: auth client leaks memory if SASL authentication is aborted (Closes: #888432) * [0dc98c6] Do not patch all-settings.c; regenerate it at build time instead. Thanks to Aki Tuomi! * [e678e3b] Bump dh compat to 11 + B-D on debhelper (>= 11~) + Use dh_installsystemd instead of dh_systemd_enable * [271b290] Bump Standards-Version to 4.1.3; no changes needed * [3cd6715] d/copyright: bump upstream and debian years * [380d1ac] Drop the ENABLED flag from /etc/default/dovecot (but let the initscript handle it if it exists) * [97d6fae] d/watch: switch upstream URL to https:// Checksums-Sha1: 7aa51b628c06dc1d14b2581deac96fafdfe6ca47 3192 dovecot_2.2.34-2~bpo9+1.dsc b6bfc245b231377223b7ea5b1c6622c21e15aa05 883172 dovecot_2.2.34-2~bpo9+1.debian.tar.xz 7d450dcd4a17a4c9da4f8d33654a05bc4e8500b9 10244648 dovecot-core-dbgsym_2.2.34-2~bpo9+1_amd64.deb 5bec4d6a285a537f191ac534c210935133596cc2 3561832 dovecot-core_2.2.34-2~bpo9+1_amd64.deb 12cc6d4e42b62a9b55c058e0cd2dd517c98f4ea0 1128384 dovecot-dev_2.2.34-2~bpo9+1_amd64.deb b0597fc95ad7248aa7fcdd5e482189cff2410b07 18748 dovecot-gssapi-dbgsym_2.2.34-2~bpo9+1_amd64.deb c197dad86904ccd08a46f48dd052904cfeae40c2 828990 dovecot-gssapi_2.2.34-2~bpo9+1_amd64.deb 2396d02edd33e46b9e320586f7310def12a68885 711656 dovecot-imapd-dbgsym_2.2.34-2~bpo9+1_amd64.deb ff35f5cba70a788f3f3ce2017d15f3712d9389af 969462 dovecot-imapd_2.2.34-2~bpo9+1_amd64.deb b3e95968cf9857463333bbdd24717c9a2da9af95 597364 dovecot-ldap-dbgsym_2.2.34-2~bpo9+1_amd64.deb 6287495eb703279a96b2e054aafa10be782b28d0 1038360 dovecot-ldap_2.2.34-2~bpo9+1_amd64.deb 9d291b6f0a78b9758f9776bc641ac0b8808ec30f 85188 dovecot-lmtpd-dbgsym_2.2.34-2~bpo9+1_amd64.deb 12f33807d7875f3e6b09e375dc7c26aff376eaf6 842998 dovecot-lmtpd_2.2.34-2~bpo9+1_amd64.deb 9643b0f8d5063bfedc3d0e52d671aab6a8c00d18 135098 dovecot-lucene-dbgsym_2.2.34-2~bpo9+1_amd64.deb cd0e47f8ce8304378787b5278f0d06ada6c2f327 847358 dovecot-lucene_2.2.34-2~bpo9+1_amd64.deb 046f0a3bc554718cf1792a944024832c6f5154ee 134162 dovecot-managesieved-dbgsym_2.2.34-2~bpo9+1_amd64.deb 5d214eec42b631f338de627af662e3368614ddb4 859404 dovecot-managesieved_2.2.34-2~bpo9+1_amd64.deb 509c2352b5165091e3c2cc407204b5a8b7a775c9 20522 dovecot-mysql-dbgsym_2.2.34-2~bpo9+1_amd64.deb 57837bc4b406ab9b9596c5f3ffba2931a46d2666 829948 dovecot-mysql_2.2.34-2~bpo9+1_amd64.deb c1a8b967c331cb209b6635b3a355b59386630810 24360 dovecot-pgsql-dbgsym_2.2.34-2~bpo9+1_amd64.deb daacefbdc69bc0cb5253049c483ced998524d799 832732 dovecot-pgsql_2.2.34-2~bpo9+1_amd64.deb f84ed29572fd943f2bf37461e2ec5ef96fd12c7d 82232 dovecot-pop3d-dbgsym_2.2.34-2~bpo9+1_amd64.deb 85b7c8e428d1fe98fb27b583581a4727d69d8a5f 849806 dovecot-pop3d_2.2.34-2~bpo9+1_amd64.deb 7c3f62518fa113941c81158f89feff49a6d7d186 1651906 dovecot-sieve-dbgsym_2.2.34-2~bpo9+1_amd64.deb 096f754d2f413da1c45c9233fcf6c875f071bdb1 1124428 dovecot-sieve_2.2.34-2~bpo9+1_amd64.deb b6d71413dcdb74d6d94c96cbfedab39de0ff9ecc 91650 dovecot-solr-dbgsym_2.2.34-2~bpo9+1_amd64.deb 10bb32e3a35900fb7a4771580a7920a3b71a5bbb 840568 dovecot-solr_2.2.34-2~bpo9+1_amd64.deb 0f91eefb3615dd9f8ec4f99bd7324c6ba9f19d34 12760 dovecot-sqlite-dbgsym_2.2.34-2~bpo9+1_amd64.deb 309a92a3d114e36e6df40338c26e6fe7a3e4295a 827984 dovecot-sqlite_2.2.34-2~bpo9+1_amd64.deb ff7c891dfc69d4267ce3e42d16d79d177d8dabc3 15951 dovecot_2.2.34-2~bpo9+1_amd64.buildinfo Checksums-Sha256: ed933df6659fc69b3174b3880244e91ec00a9f2dee5d6a77d629c5b065618dcc 3192 dovecot_2.2.34-2~bpo9+1.dsc f8c7675095497f24faaee674c463ed8092a2e779373fa09f2cf0fc0369270f2a 883172 dovecot_2.2.34-2~bpo9+1.debian.tar.xz dda8f2e7088c76ef1d337c0528de2295ede1b9e54941ae51493bfbd86263736c 10244648 dovecot-core-dbgsym_2.2.34-2~bpo9+1_amd64.deb bb33d24efd0a71177794f615c5607b556442e05d693ffc83807fb339e1eac72d 3561832 dovecot-core_2.2.34-2~bpo9+1_amd64.deb f08d05baad7726a6fc9c9322c8d5fb2cc02da64ad388518582baf33475aea788 1128384 dovecot-dev_2.2.34-2~bpo9+1_amd64.deb 924c5ddbfab684cd36aaebfb457d0ae2d4c85a05c57732f094ba40f517303f1b 18748 dovecot-gssapi-dbgsym_2.2.34-2~bpo9+1_amd64.deb 815a2baba38d5b181bdd1d04d678262d0a2eb51e758b46a25d22ae6816fe98c1 828990 dovecot-gssapi_2.2.34-2~bpo9+1_amd64.deb f085f021eca11d1ebd3aea2ef5ea6e9990ef3e2f94ce9896a5c293928d08e08b 711656 dovecot-imapd-dbgsym_2.2.34-2~bpo9+1_amd64.deb a075052d72fcfa09088b90c62c4470bd59f2c9895d490ef7e161b0a57e4c3435 969462 dovecot-imapd_2.2.34-2~bpo9+1_amd64.deb 86b1b77b192838ac3099e500ab3ee4a706b7bddf7a361cb5a2e0b1a090a65b54 597364 dovecot-ldap-dbgsym_2.2.34-2~bpo9+1_amd64.deb e7a210cdf83bf97edfe7220f6e80dbbe7a02ca608f15141886e036900dbc4114 1038360 dovecot-ldap_2.2.34-2~bpo9+1_amd64.deb ca95cf59e8e82f950a074a992002a666a97d53cb79d07f9ea579dd767716d2a1 85188 dovecot-lmtpd-dbgsym_2.2.34-2~bpo9+1_amd64.deb 884f6a6f37f67b6df3b6e70dff17dddf0c598a14bde04a49e8412f1c3dbf8dbb 842998 dovecot-lmtpd_2.2.34-2~bpo9+1_amd64.deb 170fa03680c4bbd11a138035dc28d8ad10ed4c227d4ea70b54bf7c5be5abff0f 135098 dovecot-lucene-dbgsym_2.2.34-2~bpo9+1_amd64.deb 8adb1067f127ffef6343d64423baefaa17ca8985582a08a4fdcf4a76c2e6a61d 847358 dovecot-lucene_2.2.34-2~bpo9+1_amd64.deb eaf59b547e73c7dcf10433a766807d25b3862468a9b776918d42e3321c757459 134162 dovecot-managesieved-dbgsym_2.2.34-2~bpo9+1_amd64.deb 92a62bd4428deb21ee504013eb601803b0b7a6a37c2e36869c6ac8dadbc436f5 859404 dovecot-managesieved_2.2.34-2~bpo9+1_amd64.deb 70ce9929621450e9f4477212e34bb381c76a21ed5cd6cd4a6c2b3318ee64d693 20522 dovecot-mysql-dbgsym_2.2.34-2~bpo9+1_amd64.deb 299bd4f0886eb432d0a1725baf46438f799a3a75ef44f626ee718ca96e0ad9ae 829948 dovecot-mysql_2.2.34-2~bpo9+1_amd64.deb 6d28380c4e21960d7bad18b7081ad63bea9ab351602ea10f4af9cd39fd492d2a 24360 dovecot-pgsql-dbgsym_2.2.34-2~bpo9+1_amd64.deb e8e50b34b3d26d677ed2a989117fc23b543b1f1eb8aaf9e9c29c75fe091a9cc3 832732 dovecot-pgsql_2.2.34-2~bpo9+1_amd64.deb 661085dfbba391c3b930bfc1f1f1bad76a2a61942dbaaf55025bc08baf6a6683 82232 dovecot-pop3d-dbgsym_2.2.34-2~bpo9+1_amd64.deb 4031bb241bf65fe3a8eda7f1de435aedc6c0fcf8f14d64f849c6401a1d8f4c6e 849806 dovecot-pop3d_2.2.34-2~bpo9+1_amd64.deb 8a7a9efe2d4cf4c07c540e10b22d669dfc1a56540e4f889459bb3b8d5cff7437 1651906 dovecot-sieve-dbgsym_2.2.34-2~bpo9+1_amd64.deb f188d75ed7931410c1b43086670669a4e5e7b09fecef8f54fba7ab3c081dc7bf 1124428 dovecot-sieve_2.2.34-2~bpo9+1_amd64.deb 206c78e26a3fbb0823931819a7b10af1f23bde464c170e8102b2272fe8d1aa20 91650 dovecot-solr-dbgsym_2.2.34-2~bpo9+1_amd64.deb f05c57fa066f1ea8ed77794613038c2a5263644cb4df8e10dfe485aa083a03ef 840568 dovecot-solr_2.2.34-2~bpo9+1_amd64.deb 664530c1be0209b22908cb1afb6e01c2a6a727e81541953568d1b749d5a0f00f 12760 dovecot-sqlite-dbgsym_2.2.34-2~bpo9+1_amd64.deb b6c464863c3bb9fe58397694e53a62d6ae0bb40d9c225f3f4dfafe420a62ff3c 827984 dovecot-sqlite_2.2.34-2~bpo9+1_amd64.deb 062bb065e636df40325f1d77b2bb48b5d936d8a1b61b4f3b13845c13cd325d8f 15951 dovecot_2.2.34-2~bpo9+1_amd64.buildinfo Files: d05f8ac0527fbc8d62cf60810f76585f 3192 mail optional dovecot_2.2.34-2~bpo9+1.dsc 3c464ac0b6ef9e12f46f6c2ae74b30b1 883172 mail optional dovecot_2.2.34-2~bpo9+1.debian.tar.xz 1de960fa835f6e968ec03e9c0f24952f 10244648 debug optional dovecot-core-dbgsym_2.2.34-2~bpo9+1_amd64.deb 2d06213b36963c6e12e8196e2299dd4c 3561832 mail optional dovecot-core_2.2.34-2~bpo9+1_amd64.deb 3441c9ad9cae6e097b24d361799f1fec 1128384 mail optional dovecot-dev_2.2.34-2~bpo9+1_amd64.deb ad76b324c29393accbc7db45ffa92a26 18748 debug optional dovecot-gssapi-dbgsym_2.2.34-2~bpo9+1_amd64.deb 139e4aef147553c6cec05fe552758847 828990 mail optional dovecot-gssapi_2.2.34-2~bpo9+1_amd64.deb 19b4ac3a1e03f9092a00951c78ded1f6 711656 debug optional dovecot-imapd-dbgsym_2.2.34-2~bpo9+1_amd64.deb 373e4b640469fb107120ea0d3f4d706a 969462 mail optional dovecot-imapd_2.2.34-2~bpo9+1_amd64.deb 6111344cfe54846d7008607e1a264d4f 597364 debug optional dovecot-ldap-dbgsym_2.2.34-2~bpo9+1_amd64.deb 5f2e6991ab6496c4a3f84af80ae016b8 1038360 mail optional dovecot-ldap_2.2.34-2~bpo9+1_amd64.deb 91a4a5aea59f99faa5e1043e1886dd37 85188 debug optional dovecot-lmtpd-dbgsym_2.2.34-2~bpo9+1_amd64.deb 2e668693fa4da18eebb7b38747ad87d1 842998 mail optional dovecot-lmtpd_2.2.34-2~bpo9+1_amd64.deb b9b47aac8741366db3e78e5bceedb0f6 135098 debug optional dovecot-lucene-dbgsym_2.2.34-2~bpo9+1_amd64.deb 14c97bb7207e35207f9e4614b3bac105 847358 mail optional dovecot-lucene_2.2.34-2~bpo9+1_amd64.deb 5de626e3aa34bed0d0e5ad6fb8ed1f38 134162 debug optional dovecot-managesieved-dbgsym_2.2.34-2~bpo9+1_amd64.deb a69a7714fcc7ead0b9ec9ec1b7d0cb27 859404 mail optional dovecot-managesieved_2.2.34-2~bpo9+1_amd64.deb 202e235eff0b1c07c45f3a397c7a2495 20522 debug optional dovecot-mysql-dbgsym_2.2.34-2~bpo9+1_amd64.deb 7025ed8ecc363804381d384abdc4ee4a 829948 mail optional dovecot-mysql_2.2.34-2~bpo9+1_amd64.deb 6059b7663ab36c5589fdba4f14fd5239 24360 debug optional dovecot-pgsql-dbgsym_2.2.34-2~bpo9+1_amd64.deb ed62f2874af7d261811a034a5e393164 832732 mail optional dovecot-pgsql_2.2.34-2~bpo9+1_amd64.deb 5d15649e3e693b411429993f21e63082 82232 debug optional dovecot-pop3d-dbgsym_2.2.34-2~bpo9+1_amd64.deb 58da40f3f8dd9deb6b9fe57da3212a60 849806 mail optional dovecot-pop3d_2.2.34-2~bpo9+1_amd64.deb e2a9ab64e7a9749b63a7729837531a49 1651906 debug optional dovecot-sieve-dbgsym_2.2.34-2~bpo9+1_amd64.deb c6f7eae4c99b7b8f147359bf8dd5d287 1124428 mail optional dovecot-sieve_2.2.34-2~bpo9+1_amd64.deb 7b6e79e466884a6bde9ff574b7a3cff4 91650 debug optional dovecot-solr-dbgsym_2.2.34-2~bpo9+1_amd64.deb d4e823a04f15b9a5f597d6705d93dcea 840568 mail optional dovecot-solr_2.2.34-2~bpo9+1_amd64.deb 403078cdeb6ab7a418622a2fef2f9017 12760 debug optional dovecot-sqlite-dbgsym_2.2.34-2~bpo9+1_amd64.deb 69355abdf9d9c9471759852e2927f2e2 827984 mail optional dovecot-sqlite_2.2.34-2~bpo9+1_amd64.deb 06d8592fda81af2dc574d966e88c8947 15951 mail optional dovecot_2.2.34-2~bpo9+1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEPgL9ZlYpWVIRC6uZ9RsYxyAkgiQFAlqZk8kACgkQ9RsYxyAk giSnow/8D6Nv2Cps8rT1AoQpavSEmynw3yAQvlX2MJMvEQR7btSsWTKWPsr9i8ep ju4XpNGPUqAcypX1avPsqkiTRsmF6/30CSBdtHDuo1W4ahufdCHLAkPsZwDZU0pc WCdLQUHxjxSvsJF5aYFt37DATWrQ5ZDXRnhISNNFrwt816FQzSCxXWw9adCRJ/K6 4HZk/fu4jimLTsnWyGjlTkMVRwx3MtMBuQ/RlKDCsDfEbrVDnoE7dk6KyPb/RG5C p3xX+WpoJz19OdQZ3PWqxPu6l9WW+j8GIMsFQBa2NiVv9M1Jae3N60bavFPnPo3G BWbG9cR/0G1dDkhqhOwFL7GHc0SeMA9/xx3a3d9fE0/2aDiYu8kVWNmCJIWWpLnz +tZLgc1c0lA9gs1QDeCugEg3rR3M6h8iU3Ee1igQnvXBV0ZqxjU2d5J4tHUsnXhr IukcBrnQ+ondD2jlKlMxHf2on/RND4RSKo9ed5nc/6m6f2iz0JHnMc86kNP/2e5H adBYqUiKjOMi1OXqseQ2izkv26kCuuB3PV20SVky5Xr3S5S2Q4Zl9w/L6j55CAuS aFuktSPvFL7DY388hsJnbXNM6JhKhvXMfssAf/OOPGNbQL+EBPePMNAk2zvZBEIL YvxHNuj3gnLcmUV08amewrWF9OP+90eTnho9nIKwDoO/sCTqQuc= =LeFB -----END PGP SIGNATURE-----