From 92131c83dbc2ccba80c04efcd07b28852a648cf2 Mon Sep 17 00:00:00 2001 From: Matthias Andree Date: Tue, 9 Feb 2010 10:41:30 +0100 Subject: Add CVE for sdump X.509 display bug in 6.3.11-6.3.13. --- NEWS | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) (limited to 'NEWS') diff --git a/NEWS b/NEWS index c8ee0933..e2c04976 100644 --- a/NEWS +++ b/NEWS @@ -67,9 +67,9 @@ fetchmail 6.3.15 (not yet released): fetchmail 6.3.14 (released 2010-02-05, 25487 LoC): # SECURITY FIXES -* SSL/TLS certificate information is now also reported properly on computers - that consider the "char" type signed. Fixes malloc() buffer overrun. - Workaround for older versions: do not use verbose mode. +* CVE-2010-0562: SSL/TLS certificate information is now also reported properly + on computers that consider the "char" type signed. Fixes malloc() buffer + overrun. Workaround for older versions: do not use verbose mode. See fetchmail-SA-2010-01.txt for details, including a minimal patch. # BUG FIXES -- cgit v1.2.3