Bug#627443: CVE-2011-1929

2011-05-20 Thread Marco Nenciarini
On 20/05/2011 18:44, Moritz Muehlenhoff wrote: > Package: dovecot > Severity: grave > Tags: security > > Hi Dovecot maintainers, > CVE-2011-1929 was assigned to the following issue fixed in > 1.2.17 and 2.0.13: > > | Fixed potential crashes and other problems when parsing > | header names that con

Bug#627443: CVE-2011-1929

2011-05-20 Thread Timo Sirainen
On Fri, 2011-05-20 at 18:44 +0200, Moritz Muehlenhoff wrote: > | Fixed potential crashes and other problems when parsing > | header names that contained NUL characters. > > Could you contact upstream wrt the exact impact? What is > being crashed here, can someone only crash a delivery > thread or

Bug#627443: CVE-2011-1929

2011-05-20 Thread Marco Nenciarini
On 20/05/2011 18:44, Moritz Muehlenhoff wrote: > Package: dovecot > Severity: grave > Tags: security > > Hi Dovecot maintainers, > CVE-2011-1929 was assigned to the following issue fixed in > 1.2.17 and 2.0.13: > > | Fixed potential crashes and other problems when parsing > | header names that co

Bug#627443: CVE-2011-1929

2011-05-20 Thread Moritz Muehlenhoff
Package: dovecot Severity: grave Tags: security Hi Dovecot maintainers, CVE-2011-1929 was assigned to the following issue fixed in 1.2.17 and 2.0.13: | Fixed potential crashes and other problems when parsing | header names that contained NUL characters. http://dovecot.org/pipermail/dovecot/2011-