Timo, thanks so much for your prompt response!

> On 15. Feb 2020, at 2.01, Bradley M. Kuhn <bk...@ebb.org> wrote:
>> Package: dovecot-sieve
>> Version: 1:2.3.4.1-5+deb10u1
>> Severity: important
>>    $ sieve-test -t - -Tlevel=tests test.sieve multipart.eml  
>> that  reliably generates a segfault for me.

Timo Sirainen wrote at 02:26 (PST) on Monday:
> Fixed by 
> https://github.com/dovecot/pigeonhole/commit/daf4a721c5e8606ceded426d7b882718fb22b8a9

Seems the right thing to do would be to backport that patch to the versions
in Debian stretch and buster as a security update, no?

I see there is a role address for the team maintaining the dovecot package.
I'd offer to do the backport although I admittedly haven't done it before,
but I'm willing to figure out how if it'd be useful.  Would it be useful for
me to do that?

-- 

Bradley M. Kuhn - he/him

Pls. support the charity where I work, Software Freedom Conservancy:
https://sfconservancy.org/supporter/

Reply via email to