Received: by mail.netbsd.org (Postfix, from userid 605) id 2011484E02; Thu, 29 Aug 2019 01:07:26 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 9B17684D50 for ; Thu, 29 Aug 2019 01:07:25 +0000 (UTC) X-Virus-Scanned: amavisd-new at netbsd.org Received: from mail.netbsd.org ([IPv6:::1]) by localhost (mail.netbsd.org [IPv6:::1]) (amavisd-new, port 10025) with ESMTP id 37RvqR3J-fLP for ; Thu, 29 Aug 2019 01:07:25 +0000 (UTC) Received: from cvs.NetBSD.org (ivanova.netbsd.org [199.233.217.197]) by mail.netbsd.org (Postfix) with ESMTP id 1416D84D3A for ; Thu, 29 Aug 2019 01:07:25 +0000 (UTC) Received: by cvs.NetBSD.org (Postfix, from userid 500) id 08554FBF4; Thu, 29 Aug 2019 01:07:25 +0000 (UTC) Content-Transfer-Encoding: 7bit Content-Type: multipart/mixed; boundary="_----------=_1567040845136640" MIME-Version: 1.0 Date: Thu, 29 Aug 2019 01:07:25 +0000 From: "Takahiro Kambe" Subject: CVS commit: pkgsrc/mail/dovecot2-pigeonhole To: pkgsrc-changes@NetBSD.org Reply-To: taca@netbsd.org X-Mailer: log_accum Message-Id: <20190829010725.08554FBF4@cvs.NetBSD.org> Sender: pkgsrc-changes-owner@NetBSD.org List-Id: pkgsrc-changes.NetBSD.org Precedence: bulk List-Unsubscribe: This is a multi-part message in MIME format. --_----------=_1567040845136640 Content-Disposition: inline Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="UTF-8" Module Name: pkgsrc Committed By: taca Date: Thu Aug 29 01:07:24 UTC 2019 Modified Files: pkgsrc/mail/dovecot2-pigeonhole: Makefile distinfo Log Message: mail/dovecot2-pigeonhole: update to 0.5.7.2 Update dovecot2-pigeonhole to 0.5.7.2. Changes ------- * CVE-2019-11500: ManageSieve protocol parser does not properly handle NUL byte   when scanning data in quoted strings, leading to out of bounds heap   memory writes. Found by Nick Roessler and Rafi Rubin. To generate a diff of this commit: cvs rdiff -u -r1.51 -r1.52 pkgsrc/mail/dovecot2-pigeonhole/Makefile cvs rdiff -u -r1.38 -r1.39 pkgsrc/mail/dovecot2-pigeonhole/distinfo Please note that diffs are not public domain; they are subject to the copyright notices on the relevant files. --_----------=_1567040845136640 Content-Disposition: inline Content-Length: 1968 Content-Transfer-Encoding: binary Content-Type: text/x-diff; charset=us-ascii Modified files: Index: pkgsrc/mail/dovecot2-pigeonhole/Makefile diff -u pkgsrc/mail/dovecot2-pigeonhole/Makefile:1.51 pkgsrc/mail/dovecot2-pigeonhole/Makefile:1.52 --- pkgsrc/mail/dovecot2-pigeonhole/Makefile:1.51 Wed Jul 24 18:14:42 2019 +++ pkgsrc/mail/dovecot2-pigeonhole/Makefile Thu Aug 29 01:07:24 2019 @@ -1,6 +1,6 @@ -# $NetBSD: Makefile,v 1.51 2019/07/24 18:14:42 nia Exp $ +# $NetBSD: Makefile,v 1.52 2019/08/29 01:07:24 taca Exp $ -DISTNAME= dovecot-2.3-pigeonhole-0.5.7.1 +DISTNAME= dovecot-2.3-pigeonhole-0.5.7.2 PKGNAME= ${DISTNAME:S/-2.3-/-/} CATEGORIES= mail MASTER_SITES= http://pigeonhole.dovecot.org/releases/2.3/ Index: pkgsrc/mail/dovecot2-pigeonhole/distinfo diff -u pkgsrc/mail/dovecot2-pigeonhole/distinfo:1.38 pkgsrc/mail/dovecot2-pigeonhole/distinfo:1.39 --- pkgsrc/mail/dovecot2-pigeonhole/distinfo:1.38 Tue Jul 23 15:12:22 2019 +++ pkgsrc/mail/dovecot2-pigeonhole/distinfo Thu Aug 29 01:07:24 2019 @@ -1,7 +1,7 @@ -$NetBSD: distinfo,v 1.38 2019/07/23 15:12:22 taca Exp $ +$NetBSD: distinfo,v 1.39 2019/08/29 01:07:24 taca Exp $ -SHA1 (dovecot-2.3-pigeonhole-0.5.7.1.tar.gz) = 90bc5b78b7ba7f2ea7f34768942e82189ab66c0a -RMD160 (dovecot-2.3-pigeonhole-0.5.7.1.tar.gz) = 1171b3e14b8fadbdc5aefcf27108f85e90fad5ea -SHA512 (dovecot-2.3-pigeonhole-0.5.7.1.tar.gz) = 121eac4ad8bc1ddc55c554d00338bb553590b6aedffcb11e34f6cba102d59bd34580cb7218bd5fe820038c004d12db73f7a27ca135c3d4a12c4449bae3216355 -Size (dovecot-2.3-pigeonhole-0.5.7.1.tar.gz) = 1857291 bytes +SHA1 (dovecot-2.3-pigeonhole-0.5.7.2.tar.gz) = 4e4336416b154380e9c53fe80b466d4324affcdf +RMD160 (dovecot-2.3-pigeonhole-0.5.7.2.tar.gz) = e274011a5c9b44d496e835a6b09f00fd5a60e72a +SHA512 (dovecot-2.3-pigeonhole-0.5.7.2.tar.gz) = 7fc8d89ee31c8e8c16a9aeaeffb591f4188de36fc80e3a30a9ae10bc5acd7ea5d5d91e077fda566e61d588d9221ec53044ce17a9cc0c9c219dbe6824558a1d60 +Size (dovecot-2.3-pigeonhole-0.5.7.2.tar.gz) = 1857602 bytes SHA1 (patch-aa) = 264399e166b5fece22bacd47b043c59f8f0f0a29 --_----------=_1567040845136640--