diff options
author | Patrick J Volkerding <volkerdi@slackware.com> | 2024-01-22 20:57:12 +0000 |
---|---|---|
committer | Eric Hameleers <alien@slackware.com> | 2024-01-22 22:30:21 +0100 |
commit | c3e723e5550c546829b1015b4959d78d0d153d21 (patch) | |
tree | dc089728c4d12f1a39d6efcb799a749b77d26419 /ChangeLog.txt | |
parent | c705d52cafb6fee40fe788f94e1812fdafb0f082 (diff) | |
download | current-c3e723e5550c546829b1015b4959d78d0d153d21.tar.gz current-c3e723e5550c546829b1015b4959d78d0d153d21.tar.xz |
Mon Jan 22 20:57:12 UTC 202420240122205712
l/SDL2_mixer-2.8.0-x86_64-1.txz: Upgraded.
l/glib2-2.78.4-x86_64-1.txz: Upgraded.
l/mozilla-nss-3.97-x86_64-1.txz: Upgraded.
n/postfix-3.8.5-x86_64-1.txz: Upgraded.
Security (inbound SMTP smuggling): with "smtpd_forbid_bare_newline
= normalize" (default "no" for Postfix < 3.9), the Postfix
SMTP server requires the standard End-of-DATA sequence
<CR><LF>.<CR><LF>, and otherwise allows command or message
content lines ending in the non-standard <LF>, processing
them as if the client sent the standard <CR><LF>.
The alternative setting, "smtpd_forbid_bare_newline = reject"
will reject any command or message that contains a bare
<LF>, and is more likely to cause problems with legitimate
clients.
For backwards compatibility, local clients are excluded by
default with "smtpd_forbid_bare_newline_exclusions =
$mynetworks".
For more information, see:
https://www.postfix.org/smtp-smuggling.html
(* Security fix *)
Diffstat (limited to 'ChangeLog.txt')
-rw-r--r-- | ChangeLog.txt | 22 |
1 files changed, 22 insertions, 0 deletions
diff --git a/ChangeLog.txt b/ChangeLog.txt index 586d15aae..d227b00e9 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,25 @@ +Mon Jan 22 20:57:12 UTC 2024 +l/SDL2_mixer-2.8.0-x86_64-1.txz: Upgraded. +l/glib2-2.78.4-x86_64-1.txz: Upgraded. +l/mozilla-nss-3.97-x86_64-1.txz: Upgraded. +n/postfix-3.8.5-x86_64-1.txz: Upgraded. + Security (inbound SMTP smuggling): with "smtpd_forbid_bare_newline + = normalize" (default "no" for Postfix < 3.9), the Postfix + SMTP server requires the standard End-of-DATA sequence + <CR><LF>.<CR><LF>, and otherwise allows command or message + content lines ending in the non-standard <LF>, processing + them as if the client sent the standard <CR><LF>. + The alternative setting, "smtpd_forbid_bare_newline = reject" + will reject any command or message that contains a bare + <LF>, and is more likely to cause problems with legitimate + clients. + For backwards compatibility, local clients are excluded by + default with "smtpd_forbid_bare_newline_exclusions = + $mynetworks". + For more information, see: + https://www.postfix.org/smtp-smuggling.html + (* Security fix *) ++--------------------------+ Sun Jan 21 20:50:08 UTC 2024 a/ed-1.20-x86_64-1.txz: Upgraded. l/SDL2_ttf-2.22.0-x86_64-1.txz: Upgraded. |