Package: dovecot
Version: 1.0.rc15-2etch1
Tags: security
Severity: important


Hi,

A security issue has been discovered in Dovecot:
http://dovecot.org/list/dovecot-news/2007-December/000057.html

Users can be presented with wrong mailboxes if they have the same password as 
another issue. Since it requires quite a specific configuration (see URL), 
I've labeled this "important".

Unstable is already fixed, sarge is reportedly not affected. Could you see 
whether this issue is severe enough for a DSA, and if so, prepare a package 
for it?

thanks,
Thijs

Attachment: pgpoj4hZ5rhST.pgp
Description: PGP signature

Reply via email to