aboutsummaryrefslogtreecommitdiffstats
Commit message (Expand)AuthorAgeFilesLines
...
* Two levels deep of novice help.Eric S. Raymond1998-05-261-41/+43
* First hack at novice configure.Eric S. Raymond1998-05-261-2/+2
* Help is fixed.Eric S. Raymond1998-05-261-18/+19
* Fix the help stuff.Eric S. Raymond1998-05-261-7/+11
* No more novice method.Eric S. Raymond1998-05-261-47/+16
* Problems are now pretty much confined to ConfigurationEdit.Eric S. Raymond1998-05-261-93/+72
* Document the configdump option.Eric S. Raymond1998-05-251-0/+10
* Two XXXs gone.Eric S. Raymond1998-05-251-5/+6
* We can get down to user level and edit now.Eric S. Raymond1998-05-252-9/+9
* A significant step forward -- we can get down to user level now!Eric S. Raymond1998-05-251-27/+17
* Fix the idfile option.pre { line-height: 125%; } td.linenos .normal { color: inherit; background-color2-1/+2
* We can read and dump the fetchmail --configdump output now.Eric S. Raymond1998-05-251-14/+15
* This version can read a configuration into an object tree and dump it.Eric S. Raymond1998-05-252-41/+82
* Kok Seng's package to prevent UID lossage.Eric S. Raymond1998-05-252-3/+15
* Cleanup.Eric S. Raymond1998-05-251-0/+2
* Don't <-enclose MAIL FROM name if it already contains one.Eric S. Raymond1998-05-251-11/+14
* Gunter's command-line fixes.Eric S. Raymond1998-05-254-28/+92
* Before Gunther's patches.Eric S. Raymond1998-05-252-70/+70
* Top-level copy is working.Eric S. Raymond1998-05-241-49/+72
* Fix syntax error.Eric S. Raymond1998-05-241-1/+1
* Another step forward.Eric S. Raymond1998-05-241-18/+139
* Added idfile.Eric S. Raymond1998-05-241-0/+14
* Added envskip query.Eric S. Raymond1998-05-241-2/+9
* Added antispam and smtpaddress fields.Eric S. Raymond1998-05-241-1/+9
* Added mimedecode.Eric S. Raymond1998-05-241-2/+9
* Cleanup.Eric S. Raymond1998-05-241-2/+4
* This code yields a syntactically correct Python initializer thatEric S. Raymond1998-05-231-10/+26
* We can utter a Python initializer now.Eric S. Raymond1998-05-232-160/+193
* Initial revisionEric S. Raymond1998-05-231-0/+227
* Remove the fetchall kluge.Eric S. Raymond1998-05-234-35/+24
* Added configuration dumper.Eric S. Raymond1998-05-234-11/+14
* Preserve interface string through parsing.Eric S. Raymond1998-05-231-2/+14
* Global options have been consolidated into a single control block.Eric S. Raymond1998-05-235-307/+331
* Reformat news.Eric S. Raymond1998-05-231-66/+21
* *** empty log message ***Eric S. Raymond1998-05-231-1/+1
* *** empty log message ***Eric S. Raymond1998-05-231-4/+4
* Ready for release.Eric S. Raymond1998-05-231-2/+2
* Two more fixes by Gunther Leber.Eric S. Raymond1998-05-231-10/+42
* Note Henrik's bug.Eric S. Raymond1998-05-231-0/+4
* Update.Eric S. Raymond1998-05-231-25/+28
* *** empty log message ***Eric S. Raymond1998-05-221-0/+3
* Note that POP3 can peek.Eric S. Raymond1998-05-221-1/+1
* Gunther Leber's patch.Eric S. Raymond1998-05-223-4/+7
* Added mimedecode dumping.Eric S. Raymond1998-05-221-0/+3
* Added idfile.Eric S. Raymond1998-05-227-5/+14
* Must declare cmd_idfile.Eric S. Raymond1998-05-221-0/+1
* Various bug fixes.Eric S. Raymond1998-05-225-6/+21
* Core dump fix.Eric S. Raymond1998-05-171-2/+2
* Better fix for qpopper TOP problem.Eric S. Raymond1998-05-163-8/+22
* Comment tweak.Eric S. Raymond1998-05-161-1/+1
and can recover three password characters. I tested it against fetchmail, and it does work. However, using the current techniques available to attack MD5, the msg-ids sent by the server can easily be distinguished from genuine ones as they will not respect the RFC specification. In particular, they will contain non-ASCII characters. Therefore, as a security countermeasure, I think fetchmail should reject msg-ids that does not conform to the RFC. The details of the attack and the new results against MD5 needed to build it will be presented in the Fast Software Encryption conference on March 28. I can send you some more details if needed. Meanwhile, feel free to alert any one that you believe is concerned. I am already sending this mail to the maintainers of Thunderbird, Evolution, fetchmail, and mutt. KMail already seems to do enough checks on the msg-id to avoid the attack. Please CC me in any reply. -- Ga&#235;tan LEURENT </PRE> <!--endarticle--> <HR> <P><UL> <!--threads--> <LI>Previous message: <A HREF="000884.html">[fetchmail-devel] Bug#413059: --sslcheck - non-existent option in the man page </A></li> <LI>Next message: <A HREF="000889.html">[fetchmail-devel] Security vulnerability in APOP authentication </A></li> <LI> <B>Messages sorted by:</B> <a href="date.html#887">[ date ]</a> <a href="thread.html#887">[ thread ]</a> <a href="subject.html#887">[ subject ]</a> <a href="author.html#887">[ author ]</a> </LI> </UL> <hr> <a href="https://lists.berlios.de/mailman/listinfo/fetchmail-devel">More information about the fetchmail-devel mailing list</a><br> </body></html>