b333d0b822
Exim version 4.93 ----------------- JH/01 OpenSSL: With debug enabled output keying information sufficient, server side, to decode a TLS 1.3 packet capture. JH/02 OpenSSL: Suppress the sending of (stateful) TLS1.3 session tickets. Previously the default library behaviour applied, sending two, each in its own TCP segment. JH/03 Debug output for ACL now gives the config file name and line number for each verb. JH/04 The default received_header_text now uses the RFC 8314 tls cipher clause. JH/05 DKIM: ensure that dkim_domain elements are lowercased before use. JH/06 Fix buggy handling of autoreply bounce_return_size_limit, and a possible buffer overrun for (non-chunking) other transports. JH/07 GnuTLS: Our use of late (post-handshake) certificate verification, under TLS1.3, means that a server rejecting a client certificate is not visible to the client until the first read of encrypted data (typically the response to EHLO). Add detection for that case and treat it as a failed TLS connection attempt, so that the normal retry-in-clear can work (if suitably configured). JB/01 Bug 2375: fix expansions of 822 addresses having comments in local-part and/or domain. Found and fixed by Jason Betts. JH/08 Add hardening against SRV & TLSA lookups the hit CNAMEs (a nonvalid configuration). If a CNAME target was not a wellformed name pattern, a crash could result. JH/09 Logging: Fix initial listening-on line for multiple ports for an IP when the OS reports them interleaved with other addresses. JH/10 OpenSSL: Fix aggregation of messages. Previously, when PIPELINING was used both for input and for a verify callout, both encrypted, SMTP responses being sent by the server could be lost. This resulted in dropped connections and sometimes bounces generated by a peer sending to this system. JH/11 Harden plaintext authenticator against a badly misconfigured client-send string. Previously it was possible to cause undefined behaviour in a library routine (usually a crash). Found by "zerons". JH/12 Bug 2384: fix "-bP smtp_receive_timeout". Previously it returned no output. JH/13 Bug 2386: Fix builds with Dane under LibreSSL 2.9.0 onward. Some old API was removed, so update to use the newer ones. JH/14 Bug 1891: Close the log file if receiving a non-smtp message, without any timeout set, is taking a long time. Previously we would hang on to a rotated logfile "forever" if the input was arriving with long gaps (a previous attempt to fix addressed lack, for a long time, of initial input). HS/01 Bug 2390: Use message_id for tempfile creation to avoid races in a shared (NFS) environment. The length of the tempfile name is now 4 + 16 ("hdr.$message_exim_id") which might break on file systems which restrict the file name length to lower values. (It was "hdr.$pid".) HS/02 Bug 2390: Use message_id for tempfile creation to avoid races in a shared (NFS) environment. HS/03 Bug 2392: exigrep does case sensitive *option* processing (as it did for all versions <4.90). Notably -M, -m, --invert, -I may be affected. JH/15 Use unsigned when creating bitmasks in macros, to avoid build errors on some platforms for bit 31. JH/16 GnuTLS: rework ciphersuite strings under recent library versions. Thanks to changes apparently associated with TLS1.3 handling some of the APIs previously used were either nonfunctional or inappropriate. Strings like TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM__AEAD:256 and TLS1.2:ECDHE_SECP256R1__RSA_SHA256__AES_128_CBC__SHA256:128 replace the previous TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256 . This affects log line X= elements, the $tls_{in,out}_cipher variables, and the use of specific cipher names in the encrypted= ACL condition. JH/17 OpenSSL: the default openssl_options now disables ssl_v3. JH/18 GnuTLS: fix $tls_out_ocsp under hosts_request_ocsp. Previously the verification result was not updated unless hosts_require_ocsp applied. JH/19 Bug 2398: fix listing of a named-queue. Previously, even with the option queue_list_requires_admin set to false, non-admin users were denied the facility. JH/20 Bug 2389: fix server advertising of usable certificates, under GnuTLS in directory-of-certs mode. Previously they were advertised despite the documentation. JH/21 The smtp transport option "hosts_noproxy_tls" is now unset by default. A single TCP connection by a client will now hold a TLS connection open for multiple message deliveries, by default. Previoud the default was to not do so. JH/22 The smtp transport option "hosts_try_dane" now enables all hosts by default. If built with the facility, DANE will be used. The facility SUPPORT_DANE is now enabled in the prototype build Makefile "EDITME". JH/23 The build default is now for TLS to be included; the SUPPORT_TLS define is replaced with DISABLE_TLS. Either USE_GNUTLS or (the new) USE_OPENSSL must be defined and you must still, unless you define DISABLE_TLS, manage the the include-dir and library-file requirements that go with that choice. Non-TLS builds are still supported. JH/24 Fix duplicated logging of peer name/address, on a transport connection- reject under TFO. JH/25 The smtp transport option "hosts_try_fastopen" now enables all hosts by default. If the platform supports and has the facility enabled, it will be requested on all coneections. JH/26 The PIPE_CONNECT facility is promoted from experimental status and is now controlled by the build-time option SUPPORT_PIPE_CONNECT. PP/01 Unbreak heimdal_gssapi, broken in 4.92. JH/27 Bug 2404: Use the main-section configuration option "dsn_from" for success-DSN messages. Previously the From: header was always the default one for these; the option was ignored. JH/28 Fix the timeout on smtp response to apply to the whole response. Previously it was reset for every read, so a teergrubing peer sending single bytes within the time limit could extend the connection for a long time. Credit to Qualsys Security Advisory Team for the discovery. JH/29 Fix DSN Final-Recipient: field. Previously it was the post-routing delivery address, which leaked information of the results of local forwarding. Change to the original envelope recipient address, per standards. JH/30 Bug 2411: Fix DSN generation when RFC 3461 failure notification is requested. Previously not bounce was generated and a log entry of error ignored was made. JH/31 Avoid re-expansion in ${sort } expansion. (CVE-2019-13917) JH/32 Introduce a general tainting mechanism for values read from the input channel, and values derived from them. Refuse to expand any tainted values, to catch one form of exploit. JH/33 Bug 2413: Fix dkim_strict option. Previously the expansion result was unused and the unexpanded text used for the test. Found and fixed by Ruben Jenster. JH/34 Fix crash after TLS shutdown. When the TCP/SMTP channel was left open, an attempt to use a TLS library read routine dereffed a nul pointer, causing a segfault. JH/35 Bug 2409: filter out-of-spec chars from callout response before using them in our smtp response. JH/36 Have the general router option retry_use_local_part default to true when any of the restrictive preconditions are set (to anything). Previously it was only for check_local user. The change removes one item of manual configuration which is required for proper retries when a remote router handles a subset of addresses for a domain. JH/37 Appendfile: when evaluating quota use (non-quota_size_regex) take the file link count into consideration. HS/04 Fix handling of very log lines in -H files. If a -<key> <value> line caused the extension of big_buffer, the following lines were ignored. JH/38 Bug 1395: Teach the DNS negative-cache about TTL value from the SOA in accordance with RFC 2308. Previously there was no expiry, so a longlived receive process (eg. due to ACL delays) versus a short SOA value could surprise. HS/05 Handle trailing backslash gracefully. (CVE-2019-15846) JH/39 Promote DMARC support to mainline. JH/40 Bug 2452: Add a References: header to DSNs. JH/41 With GnuTLS 3.6.0 (and later) do not attempt to manage Diffie-Hellman parameters. The relevant library call is documented as "Deprecated: This function is unnecessary and discouraged on GnuTLS 3.6.0 or later. Since 3.6.0, DH parameters are negotiated following RFC7919." HS/06 Change the default of dnssec_request_domains to "*" JH/42 Bug 2545: Fix CHUNKING for all RCPT commands rejected. Previously we carried on and emitted a BDAT command, even when PIPELINING was not active. JH/43 Bug 2465: Fix taint-handling in dsearch lookup. Previously a nontainted buffer was used for the filename, resulting in a trap when tainted arguments (eg. $domain) were used. JH/44 With OpenSSL 1.1.1 (onwards) disable renegotiation for TLS1.2 and below; recommended to avoid a possible server-load attack. The feature can be re-enabled via the openssl_options main cofiguration option. JH/45 local_scan API: documented the current smtp_printf() call. This changed for version 4.90 - adding a "more data" boolean to the arguments. Bumped the ABI version number also, this having been missed previously; release versions 4.90 to 4.92.3 inclusive were effectively broken in respect of usage of smtp_printf() by either local_scan code or libraries accessed via the ${dlfunc } expansion item. Both will need coding adjustment for any calls to smtp_printf() to match the new function signature; a FALSE value for the new argument is always safe. JH/46 FreeBSD: fix use of the sendfile() syscall. The shim was not updating the file-offset (which the Linux syscall does, and exim expects); this resulted in an indefinite loop. JH/47 ARC: fix crash in signing, triggered when a configuration error failed to do ARC verification. The Authentication-Results: header line added by the configuration then had no ARC item. |
||
---|---|---|
.. | ||
akonadi | ||
alpine | ||
amavisd-milter | ||
amavisd-new | ||
anomy-sanitizer | ||
archivemail | ||
autorespond | ||
avenger | ||
balsa | ||
bbmail | ||
bmf | ||
bogofilter | ||
bulk_mailer | ||
clamsmtp | ||
claws-mail | ||
claws-mail-archive | ||
claws-mail-attachwarner | ||
claws-mail-attremover | ||
claws-mail-bogofilter | ||
claws-mail-cachesaver | ||
claws-mail-fetchinfo | ||
claws-mail-mailmbox | ||
claws-mail-managesieve | ||
claws-mail-newmail | ||
claws-mail-notification | ||
claws-mail-pgp | ||
claws-mail-pgpcore | ||
claws-mail-pgpinline | ||
claws-mail-pgpmime | ||
claws-mail-rssyl | ||
claws-mail-smime | ||
claws-mail-spamassassin | ||
claws-mail-spamreport | ||
claws-mail-synce | ||
claws-mail-tnef | ||
claws-mail-vcalendar | ||
clawsker | ||
cone | ||
coolmail | ||
courier-analog | ||
courier-imap | ||
courier-maildir | ||
courier-mta | ||
courier-unicode | ||
cucipop | ||
cue | ||
cyrus-imapd | ||
cyrus-imapd23 | ||
cyrus-imapd24 | ||
dbmail | ||
dcc | ||
deforaos-mailer | ||
deliver | ||
demime | ||
distribute | ||
dk-milter | ||
dkim-milter | ||
dnsbl-milter | ||
dot-forward | ||
dovecot | ||
dovecot2 | ||
dovecot2-gssapi | ||
dovecot2-ldap | ||
dovecot2-mysql | ||
dovecot2-pgsql | ||
dovecot2-pigeonhole | ||
dovecot2-sqlite | ||
drac | ||
dspam | ||
elm | ||
elm-me | ||
elmo | ||
enma | ||
esmtp | ||
etach | ||
etpan | ||
evolution | ||
evolution-data-server | ||
exim | ||
exim-html | ||
exim3 | ||
exmh | ||
ezmlm | ||
ezmlm-idx | ||
faces | ||
fastforward | ||
fdm | ||
fetchmail | ||
fetchmailconf | ||
fetchyahoo | ||
fix-mime-charset | ||
fml | ||
fml4 | ||
freepops | ||
fromto | ||
getmail | ||
gld | ||
gmime | ||
gmime3 | ||
gmime24 | ||
gnarwl | ||
GNUMail | ||
gnus | ||
greetdelay | ||
grepmail | ||
greylisting-spp | ||
heirloom-mailx | ||
hypermail | ||
ifile | ||
im | ||
imap-uw | ||
imap-uw-utils | ||
imapfilter | ||
imapproxy | ||
imapsync | ||
imp | ||
incm | ||
ingo | ||
isync | ||
ja-mh | ||
jchkmail | ||
kimap | ||
kmbox | ||
kmime | ||
ksmtp | ||
libesmtp | ||
libetpan | ||
libmilter | ||
libsieve | ||
libspf2 | ||
libsrs2 | ||
libsylph | ||
libytnef | ||
mail-notification | ||
mailagent | ||
mailcrypt | ||
maildrop | ||
mailfront | ||
mailgraph | ||
mailhops | ||
mailman | ||
mailsend | ||
mailserv | ||
mailsort | ||
mailsync | ||
mailwrapper | ||
mairix | ||
majordomo | ||
mb2md | ||
mblaze | ||
mdfrm | ||
mess822 | ||
metamail | ||
mew | ||
mhonarc | ||
mhpgp | ||
milter-greylist | ||
milter-manager | ||
milter-regex | ||
mime-construct | ||
mimedefang | ||
mimp | ||
mini_sendmail | ||
minimalist | ||
mopher | ||
mpop | ||
msmtp | ||
mush | ||
mutt | ||
neomutt | ||
netbiff | ||
newmail | ||
newspipe | ||
nmh | ||
nmzmail | ||
notmuch | ||
nullmailer | ||
oe2mbx | ||
offlineimap | ||
opendkim | ||
opendmarc | ||
opensmtpd | ||
OSBF-lua | ||
p5-App-Siesh | ||
p5-Catalyst-View-Email | ||
p5-Email-Abstract | ||
p5-Email-Address | ||
p5-Email-Address-List | ||
p5-Email-Address-XS | ||
p5-Email-Date | ||
p5-Email-Date-Format | ||
p5-Email-Find | ||
p5-Email-Folder | ||
p5-Email-FolderType | ||
p5-Email-LocalDelivery | ||
p5-Email-MessageID | ||
p5-Email-MIME | ||
p5-Email-MIME-Attachment-Stripper | ||
p5-Email-MIME-ContentType | ||
p5-Email-MIME-Encodings | ||
p5-Email-MIME-RFC2047 | ||
p5-Email-Reply | ||
p5-Email-Send | ||
p5-Email-Sender | ||
p5-Email-Simple | ||
p5-Email-Stuff | ||
p5-Email-Valid | ||
p5-Email-Valid-Loose | ||
p5-GMail-IMAPD | ||
p5-IMAP-Admin | ||
p5-IMAP-Client | ||
p5-Mail-Alias | ||
p5-Mail-Audit | ||
p5-Mail-AuthenticationResults | ||
p5-Mail-Box | ||
p5-Mail-Box-IMAP4 | ||
p5-Mail-Box-POP3 | ||
p5-Mail-ClamAV | ||
p5-Mail-DeliveryStatus-BounceParser | ||
p5-Mail-DKIM | ||
p5-Mail-Ezmlm | ||
p5-Mail-IMAPClient | ||
p5-Mail-ListDetector | ||
p5-Mail-Mbox-MessageParser | ||
p5-Mail-Message | ||
p5-Mail-Milter | ||
p5-Mail-POP3Client | ||
p5-Mail-RFC822-Address | ||
p5-Mail-Sender | ||
p5-Mail-Sender-Easy | ||
p5-Mail-Sendmail | ||
p5-Mail-SPF | ||
p5-Mail-SPF-Query | ||
p5-Mail-SRS | ||
p5-Mail-Transport | ||
p5-Mail-Webmail-Gmail | ||
p5-MailTools | ||
p5-MIME-Charset | ||
p5-MIME-EncWords | ||
p5-MIME-Lite | ||
p5-MIME-Lite-HTML | ||
p5-MIME-tools | ||
p5-MIME-Types | ||
p5-Net-LMTP | ||
p5-Net-ManageSieve | ||
p5-Net-SMTP-SSL | ||
p5-Net-SMTP_auth | ||
p5-Net-validMX | ||
p5-Parse-MIME | ||
p5-razor-agents | ||
p5-Sendmail-AccessDB | ||
p5-Sendmail-PMilter | ||
p5-Test-Email | ||
p5-URI-imap | ||
p5-User-Identity | ||
Pantomime | ||
pear-Auth_SASL | ||
pear-Mail | ||
pear-Mail_Mime | ||
pear-Mail_mimeDecode | ||
perdition | ||
perdition-bdb | ||
perdition-gdbm | ||
perdition-ldap | ||
perdition-mysql | ||
perdition-odbc | ||
perdition-postgresql | ||
pfqueue | ||
php-imap | ||
pine | ||
pine-pgp-filters | ||
policyd | ||
policyd-weight | ||
popa3d | ||
poppassd | ||
poppy | ||
postfix | ||
postfix-cdb | ||
postfix-ldap | ||
postfix-lmdb | ||
postfix-mysql | ||
postfix-pcre | ||
postfix-pgsql | ||
postfix-sqlite | ||
postforward | ||
postgrey | ||
postsrsd | ||
prayer | ||
procmail | ||
proxsmtp | ||
pst-utils | ||
pulsar | ||
py-aiosmtpd | ||
py-authres | ||
py-email_validator | ||
py-flufl.bounce | ||
py-libgmail | ||
py-policyd-spf | ||
py-sendmail-admin | ||
py-spf | ||
py-ukpostcodeparser | ||
py-validate-email-address | ||
pymsgauth | ||
qcheck | ||
qconfirm | ||
qgreylist | ||
qmail | ||
qmail-acceptutils | ||
qmail-autoresponder | ||
qmail-conf | ||
qmail-lint | ||
qmail-qfilter | ||
qmail-rejectutils | ||
qmail-run | ||
qmail-spp-spf | ||
qmailanalog | ||
qmHandle | ||
qmqtool | ||
qpopper | ||
qtools | ||
queue-fix | ||
queue-repair | ||
quickml | ||
R-mime | ||
rblcheck | ||
re-alpine | ||
relay-ctrl | ||
ripmime | ||
rmail-mime | ||
roundcube | ||
roundcube-plugin-enigma | ||
roundcube-plugin-password | ||
roundcube-plugin-zipdownload | ||
rspamd | ||
rss2email | ||
ruby-actionmailer42 | ||
ruby-actionmailer51 | ||
ruby-actionmailer52 | ||
ruby-mail | ||
ruby-mailfactory | ||
ruby-mime-types | ||
ruby-mime-types-data | ||
ruby-mime-types1 | ||
ruby-mime-types2 | ||
ruby-mini_mime | ||
ruby-tmail | ||
safecat | ||
sendmail | ||
sendmail-cidrexpand | ||
sendmail-qtool | ||
sendymail | ||
serialmail | ||
sid-milter | ||
sieve-connect | ||
sigrot | ||
sma | ||
smtp-vilter | ||
smtpfeed | ||
solid-pop3d | ||
spamass-milter | ||
spamassassin | ||
spamd | ||
spamdyke | ||
spamprobe | ||
sqlgrey | ||
squirrelmail | ||
squirrelmail-decode | ||
squirrelmail-locales | ||
sqwebmail | ||
ssmtp | ||
swaks | ||
sylpheed | ||
sympa | ||
t-prot | ||
teapop | ||
thunderbird | ||
thunderbird-enigmail | ||
thunderbird-l10n | ||
thunderbird52 | ||
thunderbird52-l10n | ||
thunderbird60 | ||
thunderbird60-l10n | ||
tmda | ||
tnef | ||
tnef2txt | ||
trojita | ||
turba | ||
up-imapproxy | ||
vm | ||
wl | ||
wl-snapshot | ||
wmbiff | ||
wmmail | ||
xbiff | ||
xbuffy | ||
xfce4-mailwatch-plugin | ||
xfmail | ||
xmailbox | ||
xmailwatcher | ||
YoSucker | ||
ytnef | ||
Makefile |