Bug#914632: uw-imap: CVE-2018-19518

2019-02-24 Thread Moritz Muehlenhoff
On Sun, Feb 24, 2019 at 02:53:41PM +0100, Magnus Holmgren wrote: > Perhaps wanting to run imapd via remote shell is so rare that there's no need > to write a NEWS.Debian entry? I agree, I don't think this needs a NEWS.Debian. Cheers, Moritz

Bug#914632: uw-imap: CVE-2018-19518

2019-02-24 Thread Thorsten Glaser
Hi Magnus, >Perhaps wanting to run imapd via remote shell is so rare that there's >no need to write a NEWS.Debian entry? in case of doubt just write one, it does not hurt. Are you going to upload within the next five days or so, or do you need help? (We’re at a BSP and currently fixing stuff…)

Bug#914632: uw-imap: CVE-2018-19518

2019-02-24 Thread Magnus Holmgren
lördag 23 februari 2019 kl. 15:26:25 CET skrev Salvatore Bonaccorso: > On Sun, Jan 13, 2019 at 06:24:36PM +0100, Magnus Holmgren wrote: > > söndag 13 januari 2019 kl. 08:31:28 CET skrev Salvatore Bonaccorso: > > > On Fri, Dec 28, 2018 at 10:22:53AM +0100, Moritz Mühlenhoff wrote: > > > > On Wed,

Bug#914632: uw-imap: CVE-2018-19518

2019-02-23 Thread Thorsten Glaser
Hi Magnus, >I reckon. I just haven't been able to make gbp use my long PGP key id... any progress with that? Otherwise I’d be willing to NMU your patch. Greetings from the BSP, //mirabilos -- 21:12⎜ sogar bei opensolaris haben die von der community so ziemlich jeden mist eingebaut │ man sollte

Bug#914632: uw-imap: CVE-2018-19518

2019-02-23 Thread Salvatore Bonaccorso
Hi, On Sun, Jan 13, 2019 at 06:24:36PM +0100, Magnus Holmgren wrote: > söndag 13 januari 2019 kl. 08:31:28 CET skrev Salvatore Bonaccorso: > > On Fri, Dec 28, 2018 at 10:22:53AM +0100, Moritz Mühlenhoff wrote: > > > On Wed, Dec 26, 2018 at 05:20:40PM +0100, Magnus Holmgren wrote: > > > > I'm wond

Bug#914632: uw-imap: CVE-2018-19518

2019-01-13 Thread Magnus Holmgren
söndag 13 januari 2019 kl. 08:31:28 CET skrev Salvatore Bonaccorso: > On Fri, Dec 28, 2018 at 10:22:53AM +0100, Moritz Mühlenhoff wrote: > > On Wed, Dec 26, 2018 at 05:20:40PM +0100, Magnus Holmgren wrote: > > > I'm wondering if anyone would complain if I'd disable RSH (SSH) > > > connections > >

Bug#914632: uw-imap: CVE-2018-19518

2019-01-12 Thread Salvatore Bonaccorso
Hi Magnus, On Fri, Dec 28, 2018 at 10:22:53AM +0100, Moritz Mühlenhoff wrote: > On Wed, Dec 26, 2018 at 05:20:40PM +0100, Magnus Holmgren wrote: > > > CVE-2018-19518[0]: > > > | University of Washington IMAP Toolkit 2007f on UNIX, as used in > > > | imap_open() in PHP and other products, launches

Bug#914632: uw-imap: CVE-2018-19518

2018-12-28 Thread Moritz Mühlenhoff
On Wed, Dec 26, 2018 at 05:20:40PM +0100, Magnus Holmgren wrote: > > CVE-2018-19518[0]: > > | University of Washington IMAP Toolkit 2007f on UNIX, as used in > > | imap_open() in PHP and other products, launches an rsh command (by > > | means of the imap_rimap function in c-client/imap4r1.c and the

Bug#914632: uw-imap: CVE-2018-19518

2018-12-26 Thread Magnus Holmgren
> CVE-2018-19518[0]: > | University of Washington IMAP Toolkit 2007f on UNIX, as used in > | imap_open() in PHP and other products, launches an rsh command (by > | means of the imap_rimap function in c-client/imap4r1.c and the > | tcp_aopen function in osdep/unix/tcp_unix.c) without preventing > |

Bug#914632: uw-imap: CVE-2018-19518

2018-11-25 Thread Salvatore Bonaccorso
Source: uw-imap Version: 8:2007f~dfsg-5 Severity: important Tags: security upstream Hi, The following vulnerability was published for uw-imap. CVE-2018-19518[0]: | University of Washington IMAP Toolkit 2007f on UNIX, as used in | imap_open() in PHP and other products, launches an rsh command (by