From 916abfe741d97532ceacd834c2a5229f0a67c3c5 Mon Sep 17 00:00:00 2001 From: Matthias Andree Date: Mon, 19 Aug 2019 21:30:39 +0200 Subject: Update documentation. --- design-notes.html | 12 +++++------- 1 file changed, 5 insertions(+), 7 deletions(-) (limited to 'design-notes.html') diff --git a/design-notes.html b/design-notes.html index 4aaba5cb..fc4a2c3b 100644 --- a/design-notes.html +++ b/design-notes.html @@ -26,7 +26,8 @@

Introduction

-

This document is supposed to complement This document's contents were last updated in 2006, around fetchmail 6.3.4/6.3.5 time. +It is supposed to complement Eric S. Raymond's (ESR's) design notes. The new maintainers don't agree with some of the decisions ESR made previously, and the differences and new directions will be laid @@ -35,12 +36,9 @@ the necessary code revisions have been made.

Security

-

Fetchmail was handed over in a pretty poor shape, security-wise. It will -happily talk to the network with root privileges, use sscanf() to read -remotely received data into fixed-length stack-based buffers without -length limitation and so on. A full audit is required and security -concepts will have to be applied. Random bits are:

- +

+ Fetchmail 6.2.x was handed over in a pretty poor shape, security-wise. It would happily talk to the network with root privileges, used sscanf() to read remotely received data into fixed-length stack-based buffers without length limitation and so on. A full audit is required and security concepts will have to be applied. Random bits are: +