From 6b7dcaef98313f676d649d2f59afb157f80532ad Mon Sep 17 00:00:00 2001 From: "Eric S. Raymond" Date: Wed, 8 Aug 2001 00:06:33 +0000 Subject: Ready to ship. svn path=/trunk/; revision=3447 --- NEWS | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) (limited to 'NEWS') diff --git a/NEWS b/NEWS index 65b00064..a9e4678e 100644 --- a/NEWS +++ b/NEWS @@ -2,15 +2,19 @@ (The `lines' figures total .c, .h, .l, and .y files under version control.) -* Fixed a security hole that is exploitable if fetchmail is running as root - and the attacker can either subvert the mailserver or redirect to a fake - one using DNS spoofing. Bugtraq announcement to follow soon. Thanks - to antirez@invece.org. +fetchmail-5.8.17 (Tue Aug 7 20:05:36 EDT 2001), 21056 lines: + +* SECURITY FIX: Fixed a security hole that is exploitable if fetchmail is + running as root and the attacker can either subvert the mailserver or + redirect to a fake one using DNS spoofing. Bugtraq announcement to follow + soon. Thanks to Salvatore Sanfilippo . * Eliminated second bounce on failed RCPT TO address. * Always use fetchmail host's FQDN to identify the daemon when sending bounce messages. * Embarrassing bug of the month -- somehow, `skip' wasn't being interpreted! +There are 367 people on fetchmail-friends and 608 on fetchmail-announce. + fetchmail-5.8.16 (Fri Aug 3 18:55:54 EDT 2001), 21093 lines: * Handle ! in RFC2821 Return-Path addresses properly. -- cgit v1.2.3