packages/mail
Daniel Golle 783ee334f0
exim: update to version 4.94.2
Several exploitable vulnerabilities in Exim were reported to us and are
fixed.
Local vulnerabilities
- CVE-2020-28007: Link attack in Exim's log directory
- CVE-2020-28008: Assorted attacks in Exim's spool directory
- CVE-2020-28014: Arbitrary PID file creation
- CVE-2020-28011: Heap buffer overflow in queue_run()
- CVE-2020-28010: Heap out-of-bounds write in main()
- CVE-2020-28013: Heap buffer overflow in parse_fix_phrase()
- CVE-2020-28016: Heap out-of-bounds write in parse_fix_phrase()
- CVE-2020-28015: New-line injection into spool header file (local)
- CVE-2020-28012: Missing close-on-exec flag for privileged pipe
- CVE-2020-28009: Integer overflow in get_stdinput()
Remote vulnerabilities
- CVE-2020-28017: Integer overflow in receive_add_recipient()
- CVE-2020-28020: Integer overflow in receive_msg()
- CVE-2020-28023: Out-of-bounds read in smtp_setup_msg()
- CVE-2020-28021: New-line injection into spool header file (remote)
- CVE-2020-28022: Heap out-of-bounds read and write in extract_option()
- CVE-2020-28026: Line truncation and injection in spool_read_header()
- CVE-2020-28019: Failure to reset function pointer after BDAT error
- CVE-2020-28024: Heap buffer underflow in smtp_ungetc()
- CVE-2020-28018: Use-after-free in tls-openssl.c
- CVE-2020-28025: Heap out-of-bounds read in pdkim_finish_bodyhash()

The update to 4.94.2 also integrates a fix for a printf format issue
previously addressed by a local patch which is removed.

Signed-off-by: Daniel Golle <daniel@makrotopia.org>
(cherry picked from commit c241cb12bb)
2021-11-15 20:05:26 +00:00
..
alpine alpine: try to make reproducible 2021-02-02 22:38:12 -08:00
bogofilter bogofilter: make use of PKG_BUILD_PARALLEL 2019-10-14 08:45:18 -04:00
dovecot dovecot: update to 2.3.13 2021-02-26 13:03:27 +01:00
emailrelay treewide: Run refresh on all packages 2021-02-25 01:26:05 +08:00
exim exim: update to version 4.94.2 2021-11-15 20:05:26 +00:00
fdm treewide: Run refresh on all packages 2021-02-25 01:26:05 +08:00
greyfix treewide: Run refresh on all packages 2021-02-25 01:26:05 +08:00
mailsend treewide: Run refresh on all packages 2021-02-25 01:26:05 +08:00
mblaze mblaze: new package 2021-08-19 21:26:23 +02:00
msmtp msmtp: update to version 1.8.17 2021-10-26 11:07:34 +02:00
mutt mutt: bump to 1.14.7 2020-10-08 12:58:11 +02:00
nail treewide: Run refresh on all packages 2021-02-25 01:26:05 +08:00
opendkim treewide: Run refresh on all packages 2021-02-25 01:26:05 +08:00
pigeonhole pigeonhole: bump to 0.5.14 2021-03-10 21:21:29 -03:00
postfix postfix: update to 3.5.8 2020-12-31 02:29:46 -08:00
sendmail treewide: Run refresh on all packages 2021-02-25 01:26:05 +08:00