Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-13 Thread Korte
Am Fri, 13 Jun 2014 07:07:17 +0200 schrieb Evgeni Golov : > Hi, > > On Fri, Jun 13, 2014 at 01:17:58AM +0200, Andreas Ziegler wrote: > > > is someone planning to fix that issue in squeeze-backports? > > > > although i read most of the mails on the debian-lts-related mailing > > lists and search

Re: Fwd: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-12 Thread Evgeni Golov
Hi, On Fri, Jun 13, 2014 at 01:17:58AM +0200, Andreas Ziegler wrote: > is someone planning to fix that issue in squeeze-backports? > > although i read most of the mails on the debian-lts-related mailing > lists and searched the wiki, i couldn't find information on how security > issues with pack

Fwd: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-12 Thread Andreas Ziegler
nswer to that there? https://wiki.debian.org/LTS/FAQ Regards Andreas Ziegler Original-Nachricht Betreff: [SECURITY] [DSA 2954-1] dovecot security update Weitersenden-Datum: Mon, 9 Jun 2014 18:02:51 + (UTC) Weitersenden-Von: debian-security-annou...@lists.debian.org Datum

Re: Fw: Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-11 Thread Dominic Hargreaves
On Wed, Jun 11, 2014 at 09:14:45AM +0200, Salvatore Bonaccorso wrote: > Hi, > > On Mon, Jun 09, 2014 at 10:51:48PM +0200, Andrea Zwirner wrote: > > Uops, I've erroneously sent this question to debian-security. They will > > (justly) kill me! > > > > Before it happens, just let me ask you if fix

Re: Fw: Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-11 Thread Thijs Kinkhorst
On Wed, June 11, 2014 09:14, Salvatore Bonaccorso wrote: > Before I release the package, if somebody has a further dovecot > instance running under squeeze there are prepared packages for amd64 > under: > > http://people.debian.org/~carnil/tmp/dovecot/ Confirmed that it would without problems in o

Re: Fw: Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-11 Thread matteo filippetto
2014-06-11 9:14 GMT+02:00 Salvatore Bonaccorso : > Hi, > > On Mon, Jun 09, 2014 at 10:51:48PM +0200, Andrea Zwirner wrote: >> Uops, I've erroneously sent this question to debian-security. They will >> (justly) kill me! >> >> Before it happens, just let me ask you if fixing CVE-2014-3430 is planned

Re: Fw: Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-11 Thread Salvatore Bonaccorso
Hi, On Mon, Jun 09, 2014 at 10:51:48PM +0200, Andrea Zwirner wrote: > Uops, I've erroneously sent this question to debian-security. They will > (justly) kill me! > > Before it happens, just let me ask you if fixing CVE-2014-3430 is planned in > LTS. :-) Before I release the package, if somebo

Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-10 Thread Lupe Christoph
On Tuesday, 2014-06-10 at 08:14:50 -0400, Michael Stone wrote: > On Tue, Jun 10, 2014 at 02:08:48PM +0200, Matus UHLAR - fantomas wrote: > >I want to say that debian LTS team are volunteers, but they are not "other" > >than debian security team, because some of them are in both teams. > >afaik "ot

Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-10 Thread Michael Stone
On Tue, Jun 10, 2014 at 02:08:48PM +0200, Matus UHLAR - fantomas wrote: I want to say that debian LTS team are volunteers, but they are not "other" than debian security team, because some of them are in both teams. afaik "other" would imply that people from LTS are not in the debian security tea

Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-10 Thread Matus UHLAR - fantomas
>On Tue, Jun 10, 2014 at 5:51 AM, Brandon Vincent wrote: >> Squeeze-LTS is maintained by volunteers rather than the Debian >> security team. If a package is released, a notification should be >> posted to the debian-lts-announce mailing list. On 10.06.14 07:57, Paul Wise wrote: >I guess you mea

Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-10 Thread Jeroen Dekkers
At Tue, 10 Jun 2014 12:13:35 +0200, Matus UHLAR - fantomas wrote: > > >On Tue, Jun 10, 2014 at 5:51 AM, Brandon Vincent wrote: > >> Squeeze-LTS is maintained by volunteers rather than the Debian > >> security team. If a package is released, a notification should be > >> posted to the debian-lts-an

Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-10 Thread Matus UHLAR - fantomas
On Tue, Jun 10, 2014 at 5:51 AM, Brandon Vincent wrote: Squeeze-LTS is maintained by volunteers rather than the Debian security team. If a package is released, a notification should be posted to the debian-lts-announce mailing list. On 10.06.14 07:57, Paul Wise wrote: I guess you mean s/rather

Re: Fw: Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-09 Thread Salvatore Bonaccorso
Hi Andrea, On Mon, Jun 09, 2014 at 10:51:48PM +0200, Andrea Zwirner wrote: > Uops, I've erroneously sent this question to debian-security. They > will (justly) kill me! > > Before it happens, just let me ask you if fixing CVE-2014-3430 is > planned in LTS. :-) Yes, I plan to also upload dovecot

Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-09 Thread Paul Wise
On Tue, Jun 10, 2014 at 5:51 AM, Brandon Vincent wrote: > Squeeze-LTS is maintained by volunteers rather than the Debian > security team. If a package is released, a notification should be > posted to the debian-lts-announce mailing list. I guess you mean s/rather/other/ there? People are going

Fw: Re: [SECURITY] [DSA 2954-1] dovecot security update

2014-06-09 Thread Andrea Zwirner
From: Andrea Zwirner To: debian-secur...@lists.debian.org Subject: Re: [SECURITY] [DSA 2954-1] dovecot security update Dovecot 1.2.15 seems to be affected [1] Will the update be available for squeeze-lts? Thanks, Andrea Zwirner [1] http://web.nvd.nist.gov/view/vuln/search-results?adv_s