The Cyrus team is proud to announce the immediate availability of a new version 
of Cyrus IMAP: 3.0.13

This release contains a fix for CVE-2019-19783, a privilege escalation 
vulnerability that permits creation of arbitrary mailboxes using the 'fileinto' 
directive in user sieve scripts.  If you allow your users to upload custom 
sieve scripts, and if you have the 'mailbox' sieve extension or the 
'anysievefolder' option enabled, you will need this upgrade.

I'm trialling hosting the release files using Github's releases feature.  
Please use the Github download links if possible, and advise if you have any 
problems!  (It may even download faster due to Github's content delivery 
network.)

Download URLs:

    
https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.0.13/cyrus-imapd-3.0.13.tar.gz
    
https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.0.13/cyrus-imapd-3.0.13.tar.gz.sig

    https://www.cyrusimap.org/releases/cyrus-imapd-3.0.13.tar.gz
    https://www.cyrusimap.org/releases/cyrus-imapd-3.0.13.tar.gz.sig

Please consult the release notes and upgrade documentation before upgrading to 
3.0.13:

    https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.13.html
    https://www.cyrusimap.org/imap/download/upgrade.html

And join us on Github at https://github.com/cyrusimap/cyrus-imapd to report 
issues, join in the deliberations of new features for the next Cyrus IMAP 
release, and to contribute to the documentation.

On behalf of the Cyrus team,

Kind regards,

ellie timoney
----
Cyrus Home Page: http://www.cyrusimap.org/
List Archives/Info: http://lists.andrew.cmu.edu/pipermail/info-cyrus/
To Unsubscribe:
https://lists.andrew.cmu.edu/mailman/listinfo/info-cyrus

Reply via email to