From e5a4131e735b5a59dbc3b4b8024e437bae84bc16 Mon Sep 17 00:00:00 2001 From: Matthias Andree Date: Tue, 31 May 2011 22:39:36 +0200 Subject: Add CVE name. --- NEWS | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'NEWS') diff --git a/NEWS b/NEWS index a72a03b8..eacede8a 100644 --- a/NEWS +++ b/NEWS @@ -59,7 +59,8 @@ removed from a 6.4.0 or newer release.) fetchmail-6.3.20 (not yet released): # SECURITY BUG FIXES -* Fetchmail runs the IMAP STARTTLS or POP3 STLS negotiation with the set timeout +* CVE-2011-1947: + Fetchmail runs the IMAP STARTTLS or POP3 STLS negotiation with the set timeout (default five minutes) now. This was reported missing, from fetchmail freezes beyond a week, by Thomas Jarosch. SSL-wrapped connections were unaffected by this timeout, so users of older -- cgit v1.2.3