summaryrefslogtreecommitdiff
path: root/devel/zlib
diff options
context:
space:
mode:
authorfrueauf <frueauf>2005-07-22 14:27:52 +0000
committerfrueauf <frueauf>2005-07-22 14:27:52 +0000
commit0b4e3b0c563a03e28c10ea72eedc2e1e9b2d5286 (patch)
tree2353da8e3a2300bd5f4b5b1402bf12885095936e /devel/zlib
parent3be04c45cbd4f16e1995ebc0ee27c856963c685e (diff)
downloadpkgsrc-0b4e3b0c563a03e28c10ea72eedc2e1e9b2d5286.tar.gz
Include patch for fetchmail 6.2.5.2 because of CAN-2005-2335.
For more details have a look at http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt Changes listed within the NEWS file since 6.2.5: fetchmail-6.2.5.2 (Fri Jul 22 01:52 GMT 2005): * NOTE: Due to a Makefile.in bug, you may need to use GNU make. * SECURITY FIX: truncate UIDL replies, lest malicious or compromised POP3 servers overflow fetchmail's stack. Debian bug #212762. This is a remote root exploit. CVE Name: CAN-2005-2335. Thanks: Miloslav Trmac for pointing out the fix in 6.2.5.1 was buggy. Thanks: Ludwig Nussel for a much simpler fix. * Critical fix: omit blank between MAIL FROM: and <user@example.org>, as this causes mail loss with some listeners. * Fix: POP2 driver wouldn't properly check authentication failure. * Sunil Shetye's fix to force fetchsizelimit to 1 for APOP and RPOP.
Diffstat (limited to 'devel/zlib')
0 files changed, 0 insertions, 0 deletions