From owner-freebsd-ports Fri Apr 28 3:50: 6 2000 Delivered-To: freebsd-ports@freebsd.org Received: from freefall.freebsd.org (freefall.FreeBSD.ORG [204.216.27.21]) by hub.freebsd.org (Postfix) with ESMTP id 023CA37BE85 for ; Fri, 28 Apr 2000 03:50:03 -0700 (PDT) (envelope-from gnats@FreeBSD.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.9.3/8.9.2) id DAA16425; Fri, 28 Apr 2000 03:50:01 -0700 (PDT) (envelope-from gnats@FreeBSD.org) Received: from ady.warpnet.ro (ady.warpnet.ro [194.102.224.1]) by hub.freebsd.org (Postfix) with ESMTP id 5804537B753; Fri, 28 Apr 2000 03:41:25 -0700 (PDT) (envelope-from ady@ady.warpnet.ro) Received: (from ady@localhost) by ady.warpnet.ro (8.9.3/8.9.3) id NAA25617; Fri, 28 Apr 2000 13:43:49 +0300 (EEST) (envelope-from ady) Message-Id: <200004281043.NAA25617@ady.warpnet.ro> Date: Fri, 28 Apr 2000 13:43:49 +0300 (EEST) From: ady@freebsd.ady.ro Reply-To: ady@freebsd.ady.ro To: FreeBSD-gnats-submit@freebsd.org Cc: Kris Kennaway , Forrest Aldrich X-Send-Pr-Version: 3.2 Subject: ports/18269: port upgrade: mail/imap-uw from 4.7b to 4.7c1 Sender: owner-freebsd-ports@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org >Number: 18269 >Category: ports >Synopsis: port upgrade: mail/imap-uw from 4.7b to 4.7c1 >Confidential: no >Severity: serious >Priority: high >Responsible: freebsd-ports >State: open >Quarter: >Keywords: >Date-Required: >Class: change-request >Submitter-Id: current-users >Arrival-Date: Fri Apr 28 03:50:01 PDT 2000 >Closed-Date: >Last-Modified: >Originator: Adrian Penisoara >Release: FreeBSD 3.4-STABLE i386 >Organization: Warp Net Technologies >Environment: This port has been tested under: * FreeBSD 3.4-STABLE i386 >Description: This is a quick update for mail/imap-uw after Mark Crispin (supposely) solved the LIST "AAAAA...." vulnerability in imapd. If this is proven to be correct then the warning message should be at least modified if not disabled (Kris ?). >How-To-Repeat: Build the port. >Fix: I've attached a compressed patchfile to upgrade the current port. I'd like to thank Kris Kennaway for his concern about this ports' security and Forrest Aldirch for sending me the notice. Adrian Penisoara Ady (@freebsd.ady.ro) begin 644 imap-uw-4.7c1.diff.gz M'XL("+5E"3D"`VEM87`M=7\^@U MX!P:33>%8D'71O=FKAKQ8J7T+^-BSH[94P(8AG%;JN6TA=&Z@1A#Y`P1'GH> MQ+9M`UW7KSC:I!$'=?"A=O%!/1Y#P[\C4%=A/`;P"X``_IQEQ31*XY'V00*& M2OV.LSR934=0KH>6 M):-9T9_`'6C M`JBQD*OFVD,Y_31Y'FMG2QGP"ABJ:)#_4A(/MD;`;;/OJG6Q,ORU$UTK9\.'Q6S'??#I6 M.TJC9%K(+\Y.6QKSAK%R4YNT?C>;%:AOVTTY8F,M:N_DDU/FVG"G(ZWH&$RI M]!`Z.LZ]=MQ9?FDYVQLZY&PY=.?*U<@@-V.D#Q[\N@]!L<010P&C*, MRYH1EW)*_-F&&\HMG/#[/9TE'J]Q@`,;A]3F(9)(WV85 :HJ7O.H1P^:?T\)]J(<$X(.`?QVURelease-Note: >Audit-Trail: >Unformatted: To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-ports" in the body of the message