Fix a Cyrus IMAPd nntpd authentication bypass and a DoS (CVE-2011-3372, CVE-2011-3481)

An authentication bypass (CVE-2011-3372) and a DoS
vulnerability (CVE-2011-3481) have been fixed in the Cyrus
IMAPd nntpd.

Fixed bugs
VUL-0: CVE-2011-3372: cyrus-imapd: Cyrus IMAPd nntpd authentication bypass
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in a
