[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Uploaded sendmail 8.9.3-22 (powerpc) to samosa



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.6
Date: Mon, 08 May 2000 12:00:00 -0500
Source: sendmail
Binary: sendmail
Architecture: powerpc
Version: 8.9.3-22
Distribution: frozen
Urgency: high
Maintainer: PowerPC Build Daemon/Daniel Jacobowitz <buildd@crack.them.org>
Description: 
 sendmail   - A powerful mail transport agent.
Closes: 24608 24612 31138 32409 34285 34405 34715 34722 34789 35548 36067 38783 39021 41325 42041 42265 43241 44035 44797 55485 60282
Changes: 
 sendmail (8.9.3-22) frozen; urgency=high
 .
   * Fix unsafe fgets in mail.local, based on the upstream patch for 8.10.1
     Non-maintainer upload by security team (thanks Wichert).
   * sendmail.cf/mailer/cyrus.m4 incompatible with Debian package
     Thanks Manoj Srivastava (closes: bug #63441)
   * revert fix for 55485 because it doesn't really solve the problem:
     the problem specifically noted in the 8.10 cf/README:
 .
     NOTICE: It is possible to relay mail through a system which the anti-relay
     rules do not prevent: the case of a system that does use FEATURE(`nouucp',
     `nospecial') (system A) and relays local messages to a mail hub (e.g., via
     LOCAL_RELAY or LUSER_RELAY) (system B).  If system B doesn't use
     FEATURE(`nouucp') at all, addresses of the form
     <example.net!user@local.host> would be relayed to <user@example.net>.
     System A doesn't recognize `!' as an address separator and therefore
     forwards it to the mail hub which in turns relays it because it came from
     a trusted local host.  So if a mailserver allows UUCP (bang-format)
     addresses, all systems from which it allows relaying should do the same
     or reject those addresses.
 .
     The bottom line here is basically that a certain *combination* of nouucp
     and non-nouucp on different hosts can open up for multi-level relaying,
     which of course makes it difficult for a pre-packaged version to do "the
     right thing", given that it can't make assumptions about what type of
     systems it gets installed on. Best is probably to not have it use
     FEATURE(nouucp) in 8.9.3, as this is (of course) the default.
     --Per Hedeland
 .
     I've taken the approach of properly warning the user in sendmailconfig
     . debian/local/sendmailconfig (closes: bug#55485)
 .
   * Remove --exec parameter from start-stop-daemon --stop as it can prevent
     orderly shutdown of sendmail during postinst (use just --PIDFILE)
     . debian/sendmail.init.d (closes: bug#60282)
   * Several older bugs got marked as NMU fixed...
    . closes: #24608,#24612,#31138,#32409,#34285,#34405,#34715
    . closes: #34722,#34789,#35548,#36067,#38783,#39021,#41325
    . closes: #42041,#42265,#43241,#44035,#44797
Files: 
 9bf7a66f6b4ab78e1bead6794219bcb5 946090 mail extra sendmail_8.9.3-22_powerpc.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.1 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE5MrOjbgOPXuCjg3cRAomJAKDIRiN8QaJLp1JCp5Qyvk9Ikz2IXACePTG0
7JS8yYoPVXFR2wGI7NbbTPs=
=0m/P
-----END PGP SIGNATURE-----



Reply to: