[sisyphus] I: dovecot-1.0.3 with small security fix

Sergey =?iso-8859-1?q?seriv_=CE=C1_parkheights=2Edyndns=2Eorg?=
Ср Авг 1 20:13:42 MSD 2007


В incoming/Sisyphus направлен dovecot-1.0.3.hg20070801-alt1.src.rpm,
обновлённый до версии 1.0.3
Среди исправлений - ошибка в безопасности в модуле ACL plugin:
v1.0.3 2007-08-01  Timo Sirainen <tss на iki.fi>
- deliver: v1.0.2's bounce fix caused message to be always saved to
  INBOX even if Sieve script had discard, reject or redirect commands.
- LDAP: auth_bind=yes and empty auth_bind_userdn leaked memory
- ACL plugin: If user was given i (insert) right for a mailbox, but
  not all s/t/w (seen, deleted, other flags) rights, COPY and APPEND
  commands weren't supposed to allow saving those flags. This is
  technically a security fix, but it's unlikely this caused problems
  for anyone.
- ACL plugin: i (insert) right didn't work unless user was also given
  l (lookup) right.

-- 
	Сергей Иванов



Подробная информация о списке рассылки Sisyphus