Bug#765473: dovecot-common: Dovecot (previous to V2.1) doesn't allow to disable SSLv3 which is bad: CVE-2014-3566

2014-10-16 Thread Henrik Langos
On 10/16/14 06:19, Thijs Kinkhorst wrote: On Wed, October 15, 2014 16:30, Henrik Langos wrote: Here's the patch: http://www.dovecot.org/pipermail/dovecot/2014-October/098244.html There is also a statement that pop/imap might be harder/impossible to exploit but I wouldn't buy tha

Bug#765473: dovecot-common: Dovecot (previous to V2.1) doesn't allow to disable SSLv3 which is bad: CVE-2014-3566

2014-10-15 Thread Henrik Langos
Package: dovecot-common Version: 1:1.2.15-7 Severity: grave Tags: security squeeze upstream Justification: user security hole Hi there, I guess everybody knows by now that CVE-2014-3566 changes the status of SSLv3 from mostly-obsolete to mostly-broken. Unfortunately dovecot previous to 2.1 doesn

Bug#638252: fixed upstream

2011-09-07 Thread Henrik Langos
Fixed upstream : http://listengine.tuxfamily.org/chrony.tuxfamily.org/chrony-dev/2011/06/msg6.html see also: https://bugs.launchpad.net/ubuntu/+source/chrony/+bug/793387 -henrik -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Troubl