-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 05 Mar 2018 02:15:33 +0200 Source: dovecot Binary: dovecot-core dovecot-dev dovecot-imapd dovecot-pop3d dovecot-lmtpd dovecot-managesieved dovecot-pgsql dovecot-mysql dovecot-sqlite dovecot-ldap dovecot-gssapi dovecot-sieve dovecot-solr dovecot-lucene dovecot-dbg Architecture: source amd64 Version: 1:2.2.27-3+deb9u2~bpo8+1 Distribution: jessie-backports Urgency: high Maintainer: Dovecot Maintainers <jaldhar-dovecot@debian.org> Changed-By: Apollon Oikonomopoulos <apoikos@debian.org> Description: dovecot-core - secure POP3/IMAP server - core files dovecot-dbg - secure POP3/IMAP server - debug symbols dovecot-dev - secure POP3/IMAP server - header files dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-lucene - secure POP3/IMAP server - Lucene support dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support Closes: 865945 888432 891819 891820 Changes: dovecot (1:2.2.27-3+deb9u2~bpo8+1) jessie-backports; urgency=medium . * Rebuild for jessie-backports. . dovecot (1:2.2.27-3+deb9u2) stretch-security; urgency=high . * [794e743] Fix CVE-2017-14461: rfc822_parse_domain information leak vulnerability (Closes: #891819) * [530ca6d] Fix CVE-2017-15130: TLS SNI config lookups are inefficient and can be used for DoS (Closes: #891820) + Use dh-autoreconf, as src/Makefile.in needs to be regenerated. Also disable dovecot_name.patch, since it changes dovecot's banner in conjunction with dh_autoreconf. * [68c2156] Fix CVE-2017-15132: memory leak on aborted SASL auth (Closes: #888432) . dovecot (1:2.2.27-3+deb9u1) stretch; urgency=medium . * [8b8226f] Fix fts-solr: escape {} chars when sending queries (Closes: #865945) * [a97cdab] Add basic usage DEP-8 tests, performing end-to-end testing using LDA, IMAP and POP3. Checksums-Sha1: 43b7053bd52269a7d545cb503e45e0dc6f03ccdf 3402 dovecot_2.2.27-3+deb9u2~bpo8+1.dsc 70888182d0b8c0d00ef73be8d7e527f41c50922b 863720 dovecot_2.2.27-3+deb9u2~bpo8+1.debian.tar.xz 1ea8efdab73e0fe68a4b54da6319059eeb69ad28 3346922 dovecot-core_2.2.27-3+deb9u2~bpo8+1_amd64.deb a014cbb7c816eaea9d28610e19f2ff55ab16639e 964934 dovecot-dev_2.2.27-3+deb9u2~bpo8+1_amd64.deb 1f1a958d796b0432f5a9b9bb6b0b7c6f832a8d38 817580 dovecot-imapd_2.2.27-3+deb9u2~bpo8+1_amd64.deb 32196498fec26389f6a29933f287a512ce3f4b39 699882 dovecot-pop3d_2.2.27-3+deb9u2~bpo8+1_amd64.deb 04530b0db5f244813452192cb98071cbfd412c73 693522 dovecot-lmtpd_2.2.27-3+deb9u2~bpo8+1_amd64.deb 8486fc51554001201b4f155a3b1e4b7f3de91d16 709538 dovecot-managesieved_2.2.27-3+deb9u2~bpo8+1_amd64.deb 5bea7be8ce0100768ecacf664152338a6bed0a60 682830 dovecot-pgsql_2.2.27-3+deb9u2~bpo8+1_amd64.deb d02951aff4cc9cd20c735482bb25ddc7afd247de 679992 dovecot-mysql_2.2.27-3+deb9u2~bpo8+1_amd64.deb 1eeb3f3496a81e85542266344abf42eb4050aed7 677870 dovecot-sqlite_2.2.27-3+deb9u2~bpo8+1_amd64.deb a67ac573007028b414204ee7a1b065c3873876ef 880820 dovecot-ldap_2.2.27-3+deb9u2~bpo8+1_amd64.deb 1a9d7b44ad7ed8da1a868daaf6a63c2cd36e7628 678972 dovecot-gssapi_2.2.27-3+deb9u2~bpo8+1_amd64.deb 7152b8685ecefc9551149a74342e748024b1862a 974036 dovecot-sieve_2.2.27-3+deb9u2~bpo8+1_amd64.deb f631e5c3fe38c9f65563c96be96687aecece166c 690836 dovecot-solr_2.2.27-3+deb9u2~bpo8+1_amd64.deb 1af621ea8bc0eb9b667084e20367291a945f8459 697876 dovecot-lucene_2.2.27-3+deb9u2~bpo8+1_amd64.deb cf28e517bd3145a2bfe118e4c8ae741c83866fd6 13507520 dovecot-dbg_2.2.27-3+deb9u2~bpo8+1_amd64.deb Checksums-Sha256: 2dbe0e9095c44e5ac672b26c46d24ea6c0710824f5fb05c880010b88b6ee423a 3402 dovecot_2.2.27-3+deb9u2~bpo8+1.dsc b4fc6b9ab4601dd76ca66f63dd0f6d73f38ad670ab09f5d322838f95efdd4a7e 863720 dovecot_2.2.27-3+deb9u2~bpo8+1.debian.tar.xz 3ecc2675fa67ef81c506f50f7f4118761dd0ebdecb85dc9ed2156da1877891ed 3346922 dovecot-core_2.2.27-3+deb9u2~bpo8+1_amd64.deb acb386a8cf6613202c8311cb240afe6a52ed4f7c29603ec0722d5f42977138e5 964934 dovecot-dev_2.2.27-3+deb9u2~bpo8+1_amd64.deb c2157a5279a8b1dfe3827700623891a7016b8d0070f32f6e2a802f97d5791033 817580 dovecot-imapd_2.2.27-3+deb9u2~bpo8+1_amd64.deb 509a933998e99711bf5896bb01756ebc64a3e1f8d7c35bd04976a9fe0cca25c2 699882 dovecot-pop3d_2.2.27-3+deb9u2~bpo8+1_amd64.deb 094102d6e497cf1262389cc9311126e08108f9df94a9db30c54ecd8d9b3ac710 693522 dovecot-lmtpd_2.2.27-3+deb9u2~bpo8+1_amd64.deb 62ed73fcc43355f993732a62f73d9adac515154b70f796b8f4ec34ff21e85479 709538 dovecot-managesieved_2.2.27-3+deb9u2~bpo8+1_amd64.deb d4bc0dd56725a2aebc29020b16422449726343481597c5bfa4de9b16296e4f65 682830 dovecot-pgsql_2.2.27-3+deb9u2~bpo8+1_amd64.deb 4c012d69ac72b3915cfe52351a34e7cc002985beef7fac3675253197faff0699 679992 dovecot-mysql_2.2.27-3+deb9u2~bpo8+1_amd64.deb 97521adf10076dd1d5ee89b9fdc7024b07938a4c2e9bda5a47775f6391d4beb0 677870 dovecot-sqlite_2.2.27-3+deb9u2~bpo8+1_amd64.deb 518a9b13d070f10b16a998ffe76ed967f4fa82c4f77f50b3d11e97d050478715 880820 dovecot-ldap_2.2.27-3+deb9u2~bpo8+1_amd64.deb fffc823952b625acc150aef2a6585d072e8ca8168b044b11bcb865bb47f09df5 678972 dovecot-gssapi_2.2.27-3+deb9u2~bpo8+1_amd64.deb 50247c692d025aa2fa1c7d8648909a3d41ca8b5c5beaa3b2ae2baceeae1a4293 974036 dovecot-sieve_2.2.27-3+deb9u2~bpo8+1_amd64.deb cdc86b4d0e548cc41437e222b1702085bf38be759c82b6884d4c62e09029ce73 690836 dovecot-solr_2.2.27-3+deb9u2~bpo8+1_amd64.deb c3ec88f47319b0dbff39f0aa4075570a4f28dbb66c600db3fee6d9419041b070 697876 dovecot-lucene_2.2.27-3+deb9u2~bpo8+1_amd64.deb db839baaf40c0adbfc0d18418dca3bb43a3a1d5f9042e11183f67c38b766a565 13507520 dovecot-dbg_2.2.27-3+deb9u2~bpo8+1_amd64.deb Files: 1929c9b1b54574bd9bbe985aee87048b 3402 mail optional dovecot_2.2.27-3+deb9u2~bpo8+1.dsc a8b6d7b89da945b87c08a314c646ab8e 863720 mail optional dovecot_2.2.27-3+deb9u2~bpo8+1.debian.tar.xz 74b8ae6aed4d2300966192f82bb30be5 3346922 mail optional dovecot-core_2.2.27-3+deb9u2~bpo8+1_amd64.deb f2321ebd427adbd262ad807a7e2c1532 964934 mail optional dovecot-dev_2.2.27-3+deb9u2~bpo8+1_amd64.deb e7e0c73082a01c0b76876f8c81d477fe 817580 mail optional dovecot-imapd_2.2.27-3+deb9u2~bpo8+1_amd64.deb 6e253d5afd6098e6e7279270e52959c0 699882 mail optional dovecot-pop3d_2.2.27-3+deb9u2~bpo8+1_amd64.deb 73734a419b5d6b53dc3f1c0f129a5cfd 693522 mail optional dovecot-lmtpd_2.2.27-3+deb9u2~bpo8+1_amd64.deb 3e30b87ffb788adf2386282a483542fd 709538 mail optional dovecot-managesieved_2.2.27-3+deb9u2~bpo8+1_amd64.deb 19b2dbc6294da30402eb3981de9d776b 682830 mail optional dovecot-pgsql_2.2.27-3+deb9u2~bpo8+1_amd64.deb 519351365244cd94a7b94c637e441e57 679992 mail optional dovecot-mysql_2.2.27-3+deb9u2~bpo8+1_amd64.deb 35b325d8df85c3bcb17de8aa615507c9 677870 mail optional dovecot-sqlite_2.2.27-3+deb9u2~bpo8+1_amd64.deb 2ccfaec9f0b5da5b89074ff9addb1ef2 880820 mail optional dovecot-ldap_2.2.27-3+deb9u2~bpo8+1_amd64.deb f79782771d7e18461919568389615d6a 678972 mail optional dovecot-gssapi_2.2.27-3+deb9u2~bpo8+1_amd64.deb fb7414ac844d15b8b17f61409486c6b9 974036 mail optional dovecot-sieve_2.2.27-3+deb9u2~bpo8+1_amd64.deb ffe75786b997fca284a4f4261b2b0b31 690836 mail optional dovecot-solr_2.2.27-3+deb9u2~bpo8+1_amd64.deb d961ff4da4d5d2e8158847cee0ab6da8 697876 mail optional dovecot-lucene_2.2.27-3+deb9u2~bpo8+1_amd64.deb abbccfb9eb6d890e6f3c87b8fb5fb143 13507520 debug extra dovecot-dbg_2.2.27-3+deb9u2~bpo8+1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEPgL9ZlYpWVIRC6uZ9RsYxyAkgiQFAlqcjfwACgkQ9RsYxyAk giRm6Q//SGAqGVLog7xuvbVe001G9ET6UO87iABQj3mTXtRCkRo/0Kx2rlPAl81L Rq7J03VSqtEtZ1WK/OlMxyTMX3hgN7Wj31l9pZc/WCx1qqCXQBmRgIoIgsoqHDSq XS1mGdnWb/0m+ij1gYXrDxsKjXwWCl8wwLfnBpP7uiH+h215Kt8d8wwMlTXx5L/R eTNZORGqBaEnJPKlcXYeR04UwcfrJV8715Q9Dg0QTMMXkEDfDnDlWMatf8VqqNsn RBgUXEJfodJNQcdrJDUcv107qZTNf7jAlPyjkdXDv+Ka2Tk+zO9kCFKl6qZoykPz GR0fjmYJKsBZTDq1SUxggalY5FaZP9oebXNm7jGR9o9KcNhA29skQYX4K6a9bq7y VXl9SSt23L/X5uEa3Oezt38q+1FUqulUh69dVRMyPZhe0PyXZtMhE0s49j86ZZMk xBUvNpeakVtjowuH1KCV7d5F7Dd3WhkF3m6X0AEdRjXLQYaWTwbH6dMvZHA57XVf RE4eTyF1FLBJbOYxBJaykPNwoPls4diXKUYId+Oxa30wov0Uf1JbIPY25k2/OTkV 3Lr5D1a3q6bJ/ZliOsoOnn+7FK2SinwxbR+Nh6gJgA6ZqPLZEGXmEeR+79WL/cWz klobPOT1MHIsgoPysFfrAUIAlRyQwFwoESRIHYJuyXeKPDRuKEc= =PI9s -----END PGP SIGNATURE-----