pkgsrc/mail/fetchmail
frueauf 5cc5034daa Include patch for fetchmail 6.2.5.2 because of CAN-2005-2335.
For more details have a look at
http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt

Changes listed within the NEWS file since 6.2.5:

fetchmail-6.2.5.2 (Fri Jul 22 01:52 GMT 2005):

* NOTE: Due to a Makefile.in bug, you may need to use GNU make.
* SECURITY FIX: truncate UIDL replies, lest malicious or compromised
  POP3 servers overflow fetchmail's stack. Debian bug #212762.
  This is a remote root exploit. CVE Name: CAN-2005-2335.
  Thanks: Miloslav Trmac for pointing out the fix in 6.2.5.1 was buggy.
  Thanks: Ludwig Nussel for a much simpler fix.
* Critical fix: omit blank between MAIL FROM: and <user@example.org>,
  as this causes mail loss with some listeners.
* Fix: POP2 driver wouldn't properly check authentication failure.
* Sunil Shetye's fix to force fetchsizelimit to 1 for APOP and RPOP.
2005-07-22 14:27:52 +00:00
..
files fetchmail should be started after mail is up and running. 2004-08-01 04:54:56 +00:00
patches Include patch for fetchmail 6.2.5.2 because of CAN-2005-2335. 2005-07-22 14:27:52 +00:00
DESCR Move pkg/ files into package's toplevel directory 2001-11-01 00:57:41 +00:00
distinfo Include patch for fetchmail 6.2.5.2 because of CAN-2005-2335. 2005-07-22 14:27:52 +00:00
Makefile Include patch for fetchmail 6.2.5.2 because of CAN-2005-2335. 2005-07-22 14:27:52 +00:00
options.mk Correct handling if gssapi and kerberos is defined. Proposal by 2005-05-30 18:06:37 +00:00
PLIST RCD_SCRIPTS_EXAMPLEDIR is no longer customizable. 2005-05-02 20:33:57 +00:00