$authenticated_fail_id variable on authentication failure. Previously
it was unset.
-JH/36 Harder the handling of string-lists. When a list consisted of a sole
+JH/36 Harden the handling of string-lists. When a list consisted of a sole
"<" character, which should be a list-separator specification, we walked
off past the nul-terimation.
AM/01 GnuTLS: repeat lowlevel read and write operations while they return error
codes indicating retry. Under TLS1.3 this becomes required.
+JH/41 Fix the loop reading a message header line to check for integer overflow,
+ and more-often against header_maxsize. Previously a crafted message could
+ induce a crash of the recive process; now the message is cleanly rejected.
+
+JH/42 Bug 2366: Fix the behaviour of the dkim_verify_signers option. It had
+ been totally disabled for all of 4.91. Discovery and fix by "Mad Alex".
+
+JH/43 Fix CVE-2019-10149
+
Exim version 4.91
-----------------