Jaldhar H. Vyas uploaded new packages which fix the following problem:
DSA-1892-1
CVE-2009-2632, CVE-2009-3235
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot
For the etch-backports distribution the problem has been fixed in
version 1.0.15-2.3+lenny1~bpo40+1
For the lenny-backports distribution the problem has been fixed in
version 1.2.4-2~bpo50+1 (note this is because the 1.2.x series include an
entirely new sieve plugin.)
Upgrade instructions
If you don't use pinning
(http://backports.org/dokuwiki/doku.php?id=instructions) you have to
update the package manually via apt-get -t lenny-backports install
<packagename>.
We recommend to pin the backports repository to 200 so that new versions
of installed backports will be installed automatically.
Package: *
Pin: release a=lenny-backports
Pin-Priority: 200
Jaldhar H. Vyas <[email protected]>