X-Git-Url: https://git.exim.org/users/heiko/exim.git/blobdiff_plain/cfbb0d24e87427488fec0315366c27cdff1fcc20..1bd642c265dae5643f16d023879043b7576f66a9:/doc/doc-txt/ChangeLog?ds=sidebyside diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog index 1b3620445..5ce54a24e 100644 --- a/doc/doc-txt/ChangeLog +++ b/doc/doc-txt/ChangeLog @@ -25,10 +25,21 @@ JH/04 Add variables $arc_domains, $arc_oldest_pass for ARC verify. Fix the JH/05 Bug 2273: Cutthrough delivery left a window where the received messsage files in the spool were present and unlocked. A queue-runner could spot them, resulting in a duplicate delivery. Fix that by doing the unlock - after the unlink. Investigation by Time Stewart. Take the opportunity to - add more error-checking on spoofile handling while that code is being + after the unlink. Investigation by Tim Stewart. Take the opportunity to + add more error-checking on spoolfile handling while that code is being messed with. +PP/01 Refuse to open a spool data file (*-D) if it's a symlink. + No known attacks, no CVE, this is defensive hardening. + +JH/06 Bug 2275: The MIME ACL unlocked the received message files early, and + a queue-runner could start a delivery while other operations were ongoing. + Cutthrough delivery was a common victim, resulting in duplicate delivery. + Found and investigated by Tim Stewart. Fix by using the open message data + file handle rather than opening another, and not locally closing it (which + releases a lock) for that case, while creating the temporary .eml format + file for the MIME ACL. Also applies to "regex" and "spam" ACL conditions. + Exim version 4.91 -----------------