openwrt-packages/mail
Daniel Golle c241cb12bb
exim: update to version 4.94.2
Several exploitable vulnerabilities in Exim were reported to us and are
fixed.
Local vulnerabilities
- CVE-2020-28007: Link attack in Exim's log directory
- CVE-2020-28008: Assorted attacks in Exim's spool directory
- CVE-2020-28014: Arbitrary PID file creation
- CVE-2020-28011: Heap buffer overflow in queue_run()
- CVE-2020-28010: Heap out-of-bounds write in main()
- CVE-2020-28013: Heap buffer overflow in parse_fix_phrase()
- CVE-2020-28016: Heap out-of-bounds write in parse_fix_phrase()
- CVE-2020-28015: New-line injection into spool header file (local)
- CVE-2020-28012: Missing close-on-exec flag for privileged pipe
- CVE-2020-28009: Integer overflow in get_stdinput()
Remote vulnerabilities
- CVE-2020-28017: Integer overflow in receive_add_recipient()
- CVE-2020-28020: Integer overflow in receive_msg()
- CVE-2020-28023: Out-of-bounds read in smtp_setup_msg()
- CVE-2020-28021: New-line injection into spool header file (remote)
- CVE-2020-28022: Heap out-of-bounds read and write in extract_option()
- CVE-2020-28026: Line truncation and injection in spool_read_header()
- CVE-2020-28019: Failure to reset function pointer after BDAT error
- CVE-2020-28024: Heap buffer underflow in smtp_ungetc()
- CVE-2020-28018: Use-after-free in tls-openssl.c
- CVE-2020-28025: Heap out-of-bounds read in pdkim_finish_bodyhash()

The update to 4.94.2 also integrates a fix for a printf format issue
previously addressed by a local patch which is removed.

Signed-off-by: Daniel Golle <daniel@makrotopia.org>
2021-05-10 04:20:47 +01:00
..
alpine alpine: try to make reproducible 2021-02-02 22:38:12 -08:00
bogofilter bogofilter: make use of PKG_BUILD_PARALLEL 2019-10-14 08:45:18 -04:00
dovecot dovecot: update to 2.3.13 2021-02-22 16:34:12 -08:00
emailrelay emailrelay: update to 2.2 2021-03-12 15:05:49 -08:00
exim exim: update to version 4.94.2 2021-05-10 04:20:47 +01:00
fdm fdm: don't use host headers 2021-04-14 02:11:40 -07:00
greyfix treewide: Run refresh on all packages 2021-02-20 16:02:15 -08:00
mailsend treewide: Run refresh on all packages 2021-02-20 16:02:15 -08:00
msmtp msmtp: update to version 1.8.14 2021-01-18 23:49:55 +01:00
mutt mutt: don't use host mailpath definition 2021-04-19 21:34:05 -03:00
nail treewide: Run refresh on all packages 2021-02-20 16:02:15 -08:00
opendkim treewide: Run refresh on all packages 2021-02-20 16:02:15 -08:00
pigeonhole pigeonhole: bump to 0.5.14 2021-03-04 09:13:20 -03:00
postfix postfix: update to 3.5.8 2020-12-31 02:29:46 -08:00
sendmail treewide: Run refresh on all packages 2021-02-20 16:02:15 -08:00