Since 2.3.1 is still in experimental (see Debian bug) I moved the
lp1771524/new/debian tag to that manually.

passed all Dovecot bugs of the last 2 years to clear out or consider on
the merge.

Reconstruct, Deconstruct and Logical prepared in git merge workflow.

Checked CVE patches to exist in 2.3.1
- CVE-2017-15132 is already included
- CVE-2017-15130 is already included
- CVE-2017-14461 is already included

There were some conf-breaking changes in 2.3, so I consider it even more
important to make it available early on Cosmic cycle as well as in the
long run towards 20.04.

Note for mail-stack delivery:
- only a few breaks replaces will remain according to case #11 on 
https://wiki.debian.org/PackageTransition until after 20.04
- we will not rm-conffile the modifications it had made since it did modify 
"its own" but dovecots config, therefore removing would be an unwanted 
modification of a users configuration

All that said ready to rebase and drop a lot this time ...

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14461

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-15130

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-15132

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1771524

Title:
  Merge newer dovecot for Cosmic

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/dovecot/+bug/1771524/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to