|
|
ru.unix.bsd- RU.UNIX.BSD ------------------------------------------------------------------ From : mitrohin a.s. 2:5020/400 26 May 2006 06:35:19 To : Slawa Olhovchenkov Subject : Re: cyrus-imapd 2.3.0-2.3.3 vulnerability --------------------------------------------------------------------------------
On Wed, May 24, 2006 at 11:13:14AM +0400, Slawa Olhovchenkov wrote:
> Hello mitrohin!
>
> 24 May 06, mitrohin a.s. writes to All:
>
> mas> I am pleased to announce the release of Cyrus IMAPd 2.3.4. This is a
> mas> BETA-quality release, reflecting that it has significant numbers of new
> mas> features that have not been tested on a wide-scale basis, although
> mas> earlier versions of this code have been running at several sites for
> mas> quite some time.
>
> mas> This release fixes a potential buffer overflow in pop3d 'subfolders'
> mas> support that exists in 2.3.0-2.3.3. Full details, see
> mas> http://www.frsirt.com/english/advisories/2006/1891
>
> mas> This release also includes several new features, including the IMAP
> mas> CONDSTORE extension, and support for BINARY APPEND.
>
> mas> For full details, please see doc/changes.html and
> mas> doc/install-upgrade.html which are included in the distribution.
>
> mas> URLs for this release:
> mas> ftp://ftp.andrew.cmu.edu/pub/cyrus/cyrus-imapd-2.3.4.tar.gz
> mas> or
> mas> http://ftp.andrew.cmu.edu/pub/cyrus/cyrus-imapd-2.3.4.tar.gz
>
> mas> Questions and comments can be directed to
> mas> info-cyrus@lists.andrew.cmu.edu (public list), or
> mas> cyrus-bugs@andrew.cmu.edu.
>
> mas> ps exploit есть.
>
> Так ведь сначала надо эти subfolders включить?
>
да.
и вот еще.
I am pleased to announce the release of Cyrus IMAPd 2.3.5. This is a
BETA-quality release, reflecting that it has significant numbers of new
features that have not been tested on a wide-scale basis, although
earlier versions of this code have been running at several sites for
quite some time.
This release fixes a bug in 2.3.4 which caused new messages to not be
displayed by clients. My apologies to all of the early adopters that
have been inconvenienced by this bug. Mailboxes that had messages
appended/delivered by 2.3.4 services will need to be reconstructed.
For full details, please see doc/changes.html and
doc/install-upgrade.html which are included in the distribution.
URLs for this release:
ftp://ftp.andrew.cmu.edu/pub/cyrus/cyrus-imapd-2.3.5.tar.gz
or
http://ftp.andrew.cmu.edu/pub/cyrus/cyrus-imapd-2.3.5.tar.gz
Questions and comments can be directed to
info-cyrus@lists.andrew.cmu.edu (public list), or cyrus-bugs@andrew.cmu.edu.
--
Kenneth Murchison
Systems Programmer
Project Cyrus Developer/Maintainer
Carnegie Mellon University
/swp
--- ifmail v.2.15dev5.3
* Origin: BSPU InterNetNews site (2:5020/400)
Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.unix.bsd/34991886a74b.html, оценка из 5, голосов 10
|