2009年9月10日

[installer 2061] cyrus-imapd-2.3.15, 2.2.13p1

cyrus-imapd-2.3.15 出ています。
また、2.2.13p1 もパッケージされ直しています(CVS ディレクトリが
残っていたり、changes に追記されていなかった)。

SIEVE のバッファオーバフローの修正が含まれています。
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2632
http://www.kb.cert.org/vuls/id/336053
http://www.us.debian.org/security/2009/dsa-1881

http://secunia.com/advisories/36629/
参照のこと。

☆ cyrus-imapd-2.3.15
http://asg.web.cmu.edu/cyrus/imapd/
ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-imapd-2.3.15.tar.gz

Changes to the Cyrus IMAP Server since 2.3.14

* Fixed CERT VU#336053 - Potential buffer overflow in Sieve.
* Added new cyr_df tool for reporting Cyrus spool partition disk
space usage.
* Fixed a crash when selecting a folder after using the SCAN command
* Split mupdate_synchronize() into network scarfing and mailbox
comparision pieces. This allows us to not lock out the mailboxes.db
and mupdate clients while scarfing the UPDATE response, which can
be quite time consuming over slow links.
* Added support for MUPDATE COMPRESS and IMAP COMPRESS commands which
help speed up bulk data commands over slow links.
* Allow frontend servers in a Murder to proxy the CREATE, DELETE,
SETACL, SETQUOTA, and GETQUOTA commands for toplevel mailboxes. In
order for a frontend to know where to CREATE a toplevel mailbox,
either the defaultserver option must be set (ALL new toplevel
mailboxes are created on this particular server), or the serverlist
option must be set (new toplevel mailboxes are created on whichever
server has the most available spool space).
* Use delayed expunge in ipurge to avoid corrupting cache file and as
a bonus make it unexpungable.
* Run daily tasks at the same time each day instead of exactly 24
hours apart to detect daylight savings changes
* Fixed Bug #2727 by immediately expunging old messages on INBOX to
INBOX.sub rename
* Fixed incorrect quota calculations on sync_server when replicating
unexpunged messages (thanks David Carter)
* Allow user rename to succeed even if the user is over quota
* Fixed a skiplist foreach bug and various datatype size issues that
caused problems on some 64 bit architectures
* Added additional logging of mailbox events if condstore is enabled
to ensure modseq values are always correctly replicated
* Fixed "DBERROR db4: environment reference count went negative" by
forking idled before opening the database environment.
* Fixed a squatter bug where any short search term (< 4 characters)
would cause squatter to return all messages regardless of the other
filters being applied


☆ cyrus-imapd-2.2.13p1
http://asg.web.cmu.edu/cyrus/imapd/
ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-imapd-2.2.13p1.tar.gz

Changes to the Cyrus IMAP Server since 2.2.13

* Fixed CERT VU#336053 - Potential buffer overflow in Sieve.

----
こがよういちろう


投稿者 xml-rpc : 2009年9月10日 08:33
役に立ちました?:
過去のフィードバック 平均:(0) 総合:(0) 投票回数:(0)
本記事へのTrackback: http://hoop.euqset.org/blog/mt-tb2006.cgi/88500
トラックバック
コメント
コメントする




画像の中に見える文字を入力してください。