oss-sec mailing list archives

Re: Critical Dovecot and Pigeonhole vulnerability


From: aki.tuomi () dovecot fi
Date: Wed, 28 Aug 2019 19:42:57 +0300 (EEST)


On 28/08/2019 19:34 Hanno Böck <hanno () hboeck de> wrote:

 
On Wed, 28 Aug 2019 19:28:18 +0300 (EEST)
aki.tuomi () dovecot fi wrote:

I can see 0.5.7.2, we even announced it today.

Ok, sorry.

What confused me: There's a "changes" link right to the Download and
that points to a changelog that was last updated in july and didn't
mention anything sounding like that bug. It's for 0.5.7, not 0.5.7.2.
You should probably fix that link (changing the URL accordingly works):
https://raw.githubusercontent.com/dovecot/pigeonhole/0.5.7.2/NEWS

-- 
Hanno Böck
https://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: FE73757FA60E4E21B937579FA5880072BBB51E42

Seems the other MUA only sent html mail and none of my replies got to the list...

The problem is now fixed and changes should indicate that fix is present.

Aki


Current thread: