Set FD_CLOEXEC on SMTP sockets after forking to handle the connection.
[users/jgh/exim.git] / doc / doc-txt / ChangeLog
index cf307014b1f3b41ac29a170fe4567af7d1d0d76c..624e0a8c70911f14f0e119a2d4122a7d3363f925 100644 (file)
@@ -89,6 +89,9 @@ DW/24 Bugzilla 1044: CVE-2010-4345 - part three: remove ALT_CONFIG_ROOT_ONLY
 DW/25 Add TRUSTED_CONFIG_PREFIX_FILE option to allow alternative configuration
       files to be used while preserving root privileges.
 
+DW/26 Set FD_CLOEXEC on SMTP sockets after forking in the daemon, to ensure
+      that rogue child processes cannot use them.
+
 
 Exim version 4.72
 -----------------