From ellie at fastmail.com Mon Dec 16 00:15:54 2019 From: ellie at fastmail.com (ellie timoney) Date: Mon, 16 Dec 2019 16:15:54 +1100 Subject: Cyrus IMAP 2.5.15 released Message-ID: <0d71f988-fcac-4ac9-90a4-b1797d1af4a7@www.fastmail.com> The Cyrus team is proud to announce the immediate availability of a new version of Cyrus IMAP: 2.5.15 This release contains a fix for CVE-2019-19783, a privilege escalation vulnerability that permits creation of arbitrary mailboxes using the 'fileinto' directive in user sieve scripts. If you allow your users to upload custom sieve scripts, and if you have the 'anysievefolder' option enabled, you will need this upgrade. I'm trialling hosting the release files using Github's releases feature. Please use the Github download links if possible, and advise if you have any problems! (It may even download faster due to Github's content delivery network.) Download URLs: https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-2.5.15/cyrus-imapd-2.5.15.tar.gz https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-2.5.15/cyrus-imapd-2.5.15.tar.gz.sig https://www.cyrusimap.org/releases/cyrus-imapd-2.5.15.tar.gz https://www.cyrusimap.org/releases/cyrus-imapd-2.5.15.tar.gz.sig Please consult the release notes before upgrading to 2.5.15: https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.15.html And join us on Github at https://github.com/cyrusimap/cyrus-imapd to report issues, join in the deliberations of new features for the next Cyrus IMAP release, and to contribute to the documentation. On behalf of the Cyrus team, Kind regards, ellie timoney From ellie at fastmail.com Mon Dec 16 00:18:12 2019 From: ellie at fastmail.com (ellie timoney) Date: Mon, 16 Dec 2019 16:18:12 +1100 Subject: Cyrus IMAP 3.0.13 released Message-ID: <029cc34e-fb55-461f-8f45-6180cc259a47@www.fastmail.com> The Cyrus team is proud to announce the immediate availability of a new version of Cyrus IMAP: 3.0.13 This release contains a fix for CVE-2019-19783, a privilege escalation vulnerability that permits creation of arbitrary mailboxes using the 'fileinto' directive in user sieve scripts. If you allow your users to upload custom sieve scripts, and if you have the 'mailbox' sieve extension or the 'anysievefolder' option enabled, you will need this upgrade. I'm trialling hosting the release files using Github's releases feature. Please use the Github download links if possible, and advise if you have any problems! (It may even download faster due to Github's content delivery network.) Download URLs: https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.0.13/cyrus-imapd-3.0.13.tar.gz https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.0.13/cyrus-imapd-3.0.13.tar.gz.sig https://www.cyrusimap.org/releases/cyrus-imapd-3.0.13.tar.gz https://www.cyrusimap.org/releases/cyrus-imapd-3.0.13.tar.gz.sig Please consult the release notes and upgrade documentation before upgrading to 3.0.13: https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.13.html https://www.cyrusimap.org/imap/download/upgrade.html And join us on Github at https://github.com/cyrusimap/cyrus-imapd to report issues, join in the deliberations of new features for the next Cyrus IMAP release, and to contribute to the documentation. On behalf of the Cyrus team, Kind regards, ellie timoney