File _patchinfo of Package patchinfo.2824
<patchinfo incident="postfixadmin"> <binary>postfixadmin</binary> <packager>cboltz</packager> <issue tracker="cve" id="CVE-2014-2655"></issue> <issue tracker="bnc" id="870434">VUL-0: CVE-2014-2655: postfixadmin: SQL injection vulnerability</issue> <category>security</category> <rating>moderate</rating> <summary>PostfixAdmin: update to 2.3.7</summary> <description>Update PostfixAdmin to 2.3.7: - fix a SQL injection in list-virtual.php (CVE-2014-2655, bnc#870434) - add support for new longer TLDs like .international - fix various small bugs - translation updates for lt and da - vacation.pl: disable use of TLS by default due to a bug in Mail::Sender 0.8.22 (you can re-enable it with $smtp_tls_allowed)</description> </patchinfo>