Subject: CVS commit: [pkgsrc-2004Q4] pkgsrc/mail/cyrus-imapd22
To: None <pkgsrc-changes@NetBSD.org>
From: Lubomir Sedlacik <salo@netbsd.org>
List: pkgsrc-changes
Date: 02/25/2005 16:48:04
Module Name:	pkgsrc
Committed By:	salo
Date:		Fri Feb 25 16:48:04 UTC 2005

Modified Files:
	pkgsrc/mail/cyrus-imapd22 [pkgsrc-2004Q4]: Makefile distinfo

Log Message:
Pullup ticket 313 - requested by Adrian Portelli
security fix for cyrus-imapd22

Patch provided by the submitter.

   Module Name:		pkgsrc
   Committed By:	adrianp
   Date:		Fri Feb 25 10:21:15 UTC 2005

   Modified Files:
   	pkgsrc/mail/cyrus-imapd22: Makefile distinfo

   Log Message:
   - Update cyrus-imapd22 from 2.2.10 to 2.2.12
   - ok'ed recht@
   - Addresses a few recent security issues:
     http://asg.web.cmu.edu/archive/message.php?mailbox=archive.info-cyrus&msg=33723
     http://asg.web.cmu.edu/archive/message.php?mailbox=archive.info-cyrus&msg=33733

   Changes to the Cyrus IMAP Server since 2.2.10

   * Fix possible single byte overflow in mailbox handling code.
   * Fix possible single byte overflows in the imapd annotate extension.
   * Fix stack buffer overflows in fetchnews (exploitable by peer news
     server), backend (exploitable by admin), and in imapd (exploitable
     by users though only on platforms where a filename may be larger
     than a mailbox name).


To generate a diff of this commit:
cvs rdiff -r1.29 -r1.29.2.1 pkgsrc/mail/cyrus-imapd22/Makefile
cvs rdiff -r1.15 -r1.15.2.1 pkgsrc/mail/cyrus-imapd22/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.