pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/trunk]: pkgsrc/mail/dovecot2 mail/dovecot2: update to 2.3.7.2



details:   https://anonhg.NetBSD.org/pkgsrc/rev/7652e6a16b3b
branches:  trunk
changeset: 338703:7652e6a16b3b
user:      taca <taca%pkgsrc.org@localhost>
date:      Thu Aug 29 01:05:20 2019 +0000

description:
mail/dovecot2: update to 2.3.7.2

Update dovecot2 and related packages to 2.3.7.2.

Changes
-------
* CVE-2019-11500: IMAP protocol parser does not properly handle NUL byte
? when scanning data in quoted strings, leading to out of bounds heap
? memory writes. Found by Nick Roessler and Rafi Rubin.

diffstat:

 mail/dovecot2/Makefile.common |   4 ++--
 mail/dovecot2/distinfo        |  10 +++++-----
 2 files changed, 7 insertions(+), 7 deletions(-)

diffs (36 lines):

diff -r c2772dac1283 -r 7652e6a16b3b mail/dovecot2/Makefile.common
--- a/mail/dovecot2/Makefile.common     Wed Aug 28 22:08:12 2019 +0000
+++ b/mail/dovecot2/Makefile.common     Thu Aug 29 01:05:20 2019 +0000
@@ -1,4 +1,4 @@
-# $NetBSD: Makefile.common,v 1.32 2019/07/23 15:11:24 taca Exp $
+# $NetBSD: Makefile.common,v 1.33 2019/08/29 01:05:20 taca Exp $
 #
 # when updating to a new release, update ABI depends in
 # the buildlink3.mk file as well, since the plugins' version
@@ -11,7 +11,7 @@
 # used by mail/dovecot2-pgsql/Makefile
 # used by mail/dovecot2-sqlite/Makefile
 
-DISTNAME=      dovecot-2.3.7.1
+DISTNAME=      dovecot-2.3.7.2
 CATEGORIES=    mail
 MASTER_SITES=  https://dovecot.org/releases/${PKGVERSION_NOREV:R:R}/
 
diff -r c2772dac1283 -r 7652e6a16b3b mail/dovecot2/distinfo
--- a/mail/dovecot2/distinfo    Wed Aug 28 22:08:12 2019 +0000
+++ b/mail/dovecot2/distinfo    Thu Aug 29 01:05:20 2019 +0000
@@ -1,9 +1,9 @@
-$NetBSD: distinfo,v 1.96 2019/07/23 15:11:24 taca Exp $
+$NetBSD: distinfo,v 1.97 2019/08/29 01:05:20 taca Exp $
 
-SHA1 (dovecot-2.3.7.1.tar.gz) = ebd6aefa6db3930d8b3af030b1ed2b88b230d4c9
-RMD160 (dovecot-2.3.7.1.tar.gz) = b2bb6c5f754d1d9b5565a20473bb4a7b5a2fa422
-SHA512 (dovecot-2.3.7.1.tar.gz) = 9addfe2be9ae745ac9164e1658e6638df96bd611d45f172e2cd1cb2c6596e4ce534674e9eea3c1d17f497555061031916e0fb9a9fbc6de0eb6034e2fd0bed3b9
-Size (dovecot-2.3.7.1.tar.gz) = 7076500 bytes
+SHA1 (dovecot-2.3.7.2.tar.gz) = cceb5ec832c73275423ec2fe16381073aa798b0c
+RMD160 (dovecot-2.3.7.2.tar.gz) = 22b84d79fa580fc73d9fc810ad4b1328471e942c
+SHA512 (dovecot-2.3.7.2.tar.gz) = 172f7f0edb884259e4c050607510aee67a35c3a20b7dd147e7c8a25a04921c18f7d6b5c85af2c69ae8c4d53791550970e471b033dbfae94253e331053b6a317d
+Size (dovecot-2.3.7.2.tar.gz) = 7076231 bytes
 SHA1 (patch-aa) = 3af01aa4a8cea1a3fb840b6243a744de77069611
 SHA1 (patch-ab) = 9db15fd853ba47ef4bf04f2adc9ab24f71ee4d1e
 SHA1 (patch-ae) = c795585df9f415ceabb28eec1ff691ee26168d3b



Home | Main Index | Thread Index | Old Index