| Summary: | Update to 2.5.7 | ||
|---|---|---|---|
| Product: | Sisyphus | Reporter: | Konstantin A Lepikhov (L.A. Kostis) <lakostis> |
| Component: | cyrus-imapd | Assignee: | Sergey Y. Afonin <asy> |
| Status: | CLOSED FIXED | QA Contact: | qa-sisyphus |
| Severity: | normal | ||
| Priority: | P3 | CC: | admsasha, asy |
| Version: | unstable | Keywords: | relnote |
| Hardware: | all | ||
| OS: | Linux | ||
| URL: | https://docs.cyrus.foundation/imap/release-notes/2.5/x/2.5.7.html | ||
У нас несовсем честный 2.5.6 - я мерджил по тегу cyrus-imapd-2.5 сильно позже релиза 2.5.6, так что вот это у нас уже есть: === commit 4c04c3b417b24a0c2a941d646d6799b32a3ba6b0 Author: Jeroen van Meeuwen (Kolab Systems) <vanmeeuwen@kolabsys.com> Date: Sat Mar 14 13:00:04 2015 +0100 Disable the use of SSLv2 / SSLv3 Resolves T52 === А вот urlfetch не успел попасть чуть-чуть. |
Changes Since 2.5.6 Security fixes CVE-2015-8077, CVE-2015-8078: protect against integer overflow in urlfetch range checks SSL changes Support for legacy SSLv2 and SSLv3 protocols has been removed Думаю, ради этого стоит обновить.