JH/20 Taint checking: disallow use of tainted data for
- the appendfile transport file and directory options
- the pipe transport command
+ - the autoreply transport file, log and once options
- file names used by the redirect router (including filter files)
+ - named-queue names
Previously this was permitted.
+JH/21 Bug 2501: Fix init call in the heimdal authenticator. Previously it
+ adjusted the size of a major service buffer; this failed because the
+ buffer was in use at the time. Change to a compile-time increase in the
+ buffer size, when this authenticator is compiled into exim.
+
+JH/22 Taint checking: move to a hybrid approach for checking. Previously, one
+ of two ways was used, depending on a build-time flag. The fast method
+ relied on assumptions about the OS and libc malloc, which were known to
+ not hold for the BSD-derived platforms, and discovered to not hold for
+ 32-bit Linux either. In fact the glibc documentation describes cases
+ where these assumptions do not hold. The new implementation tests for
+ the situation arising and actively switches over from fast to safe mode.
+
Exim version 4.93
-----------------