RC bug #527862: libmilter1.0.1: segfault in libmilter - using milter-greylist and mimedefang - both dies
- To: debian-release@lists.debian.org, Richard A Nelson <cowboy@debian.org>, "Frank B\. Brokken" <f.b.brokken@rug.nl>, George Danchev <danchev@spnet.net>, tony mancill <tmancill@debian.org>, ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>, Mike Markley <mike@markley.org>, Hilko Bengen <bengen@debian.org>, Paul Martin <pm@debian.org>, Christoph Martin <christoph.martin@uni-mainz.de>, Scott Kitterman <scott@kitterman.com>, Don Armstrong <don@debian.org>
- Cc: amavisd-new-debian-devel@lists.alioth.debian.org
- Subject: RC bug #527862: libmilter1.0.1: segfault in libmilter - using milter-greylist and mimedefang - both dies
- From: Harald Jenny <harald@a-little-linux-box.at>
- Date: Sat, 11 Dec 2010 12:52:47 +0100
- Message-id: <[🔎] 20101211115247.GA5573@harald-has.a-little-linux-box.at>
Dear release team and package maintainers,
first my apologies for this mass mailing but as the problem described in the
subject affects a dozen of programs (at least according to their Depends-field)
I thought it would be beneficial to allow everybody to participate in this
"conversation". The issue at hand is that a bug in the current version of
libmilter which is available in Debian Squeeze (8.14.3-9.4) leads to sefaults
of the affected programs when hit my milter requests. Affected packages are:
amavisd-milter
batv-milter
libbobcat2
clamav-milter
dkim-filter
libsendmail-milter-perl
milter-greylist
mimedefang
opendkim
python-milter
spamass-milter
spfmilter
As the combined number of current installations (according to popcon, state
2010-12) is 1085, I would desperately ask the release team and the sendmail
packager Richard A Nelson for a solution to this problem. Debian Sid contains
a 8.14.4-2 version of libmilter which according to my testings fixes the
problem at hand, but also introduces other changes, one of them with a security
background fixing CVE-2009-4565. May I ask for feedback from the release team
and Richard A Nelson concerning this matter?
Kind regards
Harald Jenny
Reply to: