[Bug 438363] Re: Please, fix buffer overflow vulnerability in SIEVE

2010-07-07 Thread Jamie Strandboge
cyrus-imapd-2.2 (2.2.13-14ubuntu3.1) jaunty-security; urgency=low * SECURITY UPDATE: Fix potential buffer overflows - debian/patches/0024-upstream-fix-sieve.dpatch: Use snprintf to avoid buffer overruns. Also fix for a buffer overflow in SIEVE filtering allowing for privilege

[Bug 438363] Re: Please, fix buffer overflow vulnerability in SIEVE

2010-07-06 Thread Jamie Strandboge
ACK for jaunty. Thanks Brian! Artur, while I agree DEP-3 is preferred, Brian took the patch straight from Debian and as such, we can accept it as it. Brian gave proper attribution. -- Please, fix buffer overflow vulnerability in SIEVE https://bugs.launchpad.net/bugs/438363 You received this bug

[Bug 438363] Re: Please, fix buffer overflow vulnerability in SIEVE

2010-07-06 Thread Jamie Strandboge
** Changed in: cyrus-imapd-2.2 (Ubuntu) Status: Confirmed = Fix Committed -- Please, fix buffer overflow vulnerability in SIEVE https://bugs.launchpad.net/bugs/438363 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --

[Bug 438363] Re: Please, fix buffer overflow vulnerability in SIEVE

2010-07-05 Thread Artur Rona
Brian, please replenish your patch with more informations. Follow with https://wiki.ubuntu.com/UbuntuDevelopment/PatchTaggingGuidelines -- Please, fix buffer overflow vulnerability in SIEVE https://bugs.launchpad.net/bugs/438363 You received this bug notification because you are a member of

[Bug 438363] Re: Please, fix buffer overflow vulnerability in SIEVE

2010-07-02 Thread Brian Thomason
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2009-3235 -- Please, fix buffer overflow vulnerability in SIEVE https://bugs.launchpad.net/bugs/438363 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs

[Bug 438363] Re: Please, fix buffer overflow vulnerability in SIEVE

2010-07-02 Thread Brian Thomason
** Patch added: Jaunty debdiff http://launchpadlibrarian.net/51306636/cyrus-imapd-2.2_2.2.13-14ubuntu3.1.debdiff -- Please, fix buffer overflow vulnerability in SIEVE https://bugs.launchpad.net/bugs/438363 You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 438363] Re: Please, fix buffer overflow vulnerability in SIEVE

2009-10-01 Thread Anderson
Unfortunately, I'm able to make a debdiff for Cyrus Jaunty's packages only. I don't have a testing environment for dapper, hardy, intrepid and karmic packages. -- Please, fix buffer overflow vulnerability in SIEVE https://bugs.launchpad.net/bugs/438363 You received this bug notification because