diff options
author | Eric S. Raymond <esr@thyrsus.com> | 2001-08-08 00:06:33 +0000 |
---|---|---|
committer | Eric S. Raymond <esr@thyrsus.com> | 2001-08-08 00:06:33 +0000 |
commit | 6b7dcaef98313f676d649d2f59afb157f80532ad (patch) | |
tree | 3ee5514b691254331d8db2a6a94777dd802e3122 /NEWS | |
parent | a1d005043d430e274717019b5234a75c0e88bb29 (diff) | |
download | fetchmail-6b7dcaef98313f676d649d2f59afb157f80532ad.tar.gz fetchmail-6b7dcaef98313f676d649d2f59afb157f80532ad.tar.bz2 fetchmail-6b7dcaef98313f676d649d2f59afb157f80532ad.zip |
Ready to ship.
svn path=/trunk/; revision=3447
Diffstat (limited to 'NEWS')
-rw-r--r-- | NEWS | 12 |
1 files changed, 8 insertions, 4 deletions
@@ -2,15 +2,19 @@ (The `lines' figures total .c, .h, .l, and .y files under version control.) -* Fixed a security hole that is exploitable if fetchmail is running as root - and the attacker can either subvert the mailserver or redirect to a fake - one using DNS spoofing. Bugtraq announcement to follow soon. Thanks - to antirez@invece.org. +fetchmail-5.8.17 (Tue Aug 7 20:05:36 EDT 2001), 21056 lines: + +* SECURITY FIX: Fixed a security hole that is exploitable if fetchmail is + running as root and the attacker can either subvert the mailserver or + redirect to a fake one using DNS spoofing. Bugtraq announcement to follow + soon. Thanks to Salvatore Sanfilippo <antirez@invece.org>. * Eliminated second bounce on failed RCPT TO address. * Always use fetchmail host's FQDN to identify the daemon when sending bounce messages. * Embarrassing bug of the month -- somehow, `skip' wasn't being interpreted! +There are 367 people on fetchmail-friends and 608 on fetchmail-announce. + fetchmail-5.8.16 (Fri Aug 3 18:55:54 EDT 2001), 21093 lines: * Handle ! in RFC2821 Return-Path addresses properly. |