X-Git-Url: https://git.exim.org/exim.git/blobdiff_plain/64b67b658a37dd780cc1b2fd0ef87febe461a0ba..85defcf0e9e4187107b8a1a5138ef9590ac3892c:/doc/doc-txt/ChangeLog diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog index 3e19066a9..d99b2684a 100644 --- a/doc/doc-txt/ChangeLog +++ b/doc/doc-txt/ChangeLog @@ -18,6 +18,20 @@ JH/03 Bug 2269: When presented with a received message having a stupidly large number of DKIM-Signature headers, disable DKIM verification to avoid a resource-consumption attack. The limit is set at twenty. +JH/04 Add variables $arc_domains, $arc_oldest_pass for ARC verify. Fix the + report of oldest_pass in ${authres } in consequence, and separate out + some descriptions of reasons for verification fail. + +JH/05 Bug 2273: Cutthrough delivery left a window where the received messsage + files in the spool were present and unlocked. A queue-runner could spot + them, resulting in a duplicate delivery. Fix that by doing the unlock + after the unlink. Investigation by Tim Stewart. Take the opportunity to + add more error-checking on spoolfile handling while that code is being + messed with. + +PP/01 Refuse to open a spool data file (*-D) if it's a symlink. + No known attacks, no CVE, this is defensive hardening. + Exim version 4.91 -----------------