Uploaded sendmail 8.9.3-22 (powerpc) to samosa
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.6
Date: Mon, 08 May 2000 12:00:00 -0500
Source: sendmail
Binary: sendmail
Architecture: powerpc
Version: 8.9.3-22
Distribution: frozen
Urgency: high
Maintainer: PowerPC Build Daemon/Daniel Jacobowitz <buildd@crack.them.org>
Description:
sendmail - A powerful mail transport agent.
Closes: 24608 24612 31138 32409 34285 34405 34715 34722 34789 35548 36067 38783 39021 41325 42041 42265 43241 44035 44797 55485 60282
Changes:
sendmail (8.9.3-22) frozen; urgency=high
.
* Fix unsafe fgets in mail.local, based on the upstream patch for 8.10.1
Non-maintainer upload by security team (thanks Wichert).
* sendmail.cf/mailer/cyrus.m4 incompatible with Debian package
Thanks Manoj Srivastava (closes: bug #63441)
* revert fix for 55485 because it doesn't really solve the problem:
the problem specifically noted in the 8.10 cf/README:
.
NOTICE: It is possible to relay mail through a system which the anti-relay
rules do not prevent: the case of a system that does use FEATURE(`nouucp',
`nospecial') (system A) and relays local messages to a mail hub (e.g., via
LOCAL_RELAY or LUSER_RELAY) (system B). If system B doesn't use
FEATURE(`nouucp') at all, addresses of the form
<example.net!user@local.host> would be relayed to <user@example.net>.
System A doesn't recognize `!' as an address separator and therefore
forwards it to the mail hub which in turns relays it because it came from
a trusted local host. So if a mailserver allows UUCP (bang-format)
addresses, all systems from which it allows relaying should do the same
or reject those addresses.
.
The bottom line here is basically that a certain *combination* of nouucp
and non-nouucp on different hosts can open up for multi-level relaying,
which of course makes it difficult for a pre-packaged version to do "the
right thing", given that it can't make assumptions about what type of
systems it gets installed on. Best is probably to not have it use
FEATURE(nouucp) in 8.9.3, as this is (of course) the default.
--Per Hedeland
.
I've taken the approach of properly warning the user in sendmailconfig
. debian/local/sendmailconfig (closes: bug#55485)
.
* Remove --exec parameter from start-stop-daemon --stop as it can prevent
orderly shutdown of sendmail during postinst (use just --PIDFILE)
. debian/sendmail.init.d (closes: bug#60282)
* Several older bugs got marked as NMU fixed...
. closes: #24608,#24612,#31138,#32409,#34285,#34405,#34715
. closes: #34722,#34789,#35548,#36067,#38783,#39021,#41325
. closes: #42041,#42265,#43241,#44035,#44797
Files:
9bf7a66f6b4ab78e1bead6794219bcb5 946090 mail extra sendmail_8.9.3-22_powerpc.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.1 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iD8DBQE5MrOjbgOPXuCjg3cRAomJAKDIRiN8QaJLp1JCp5Qyvk9Ikz2IXACePTG0
7JS8yYoPVXFR2wGI7NbbTPs=
=0m/P
-----END PGP SIGNATURE-----
Reply to: