X-Git-Url: https://git.exim.org/users/jgh/exim.git/blobdiff_plain/85defcf0e9e4187107b8a1a5138ef9590ac3892c..e60572454b5b9aab9bf1b050a73360674cd7af4e:/doc/doc-txt/ChangeLog?ds=sidebyside diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog index d99b2684a..881d24c25 100644 --- a/doc/doc-txt/ChangeLog +++ b/doc/doc-txt/ChangeLog @@ -32,6 +32,23 @@ JH/05 Bug 2273: Cutthrough delivery left a window where the received messsage PP/01 Refuse to open a spool data file (*-D) if it's a symlink. No known attacks, no CVE, this is defensive hardening. +JH/06 Bug 2275: The MIME ACL unlocked the received message files early, and + a queue-runner could start a delivery while other operations were ongoing. + Cutthrough delivery was a common victim, resulting in duplicate delivery. + Found and investigated by Tim Stewart. Fix by using the open message data + file handle rather than opening another, and not locally closing it (which + releases a lock) for that case, while creating the temporary .eml format + file for the MIME ACL. Also applies to "regex" and "spam" ACL conditions. + +JH/07 Bug 177: Make a random-recipient callout success visible in ACL, by setting + $sender_verify_failure/$recipient_verify_failure to "random". + +JH/08 When generating a selfsigned cert, use serial number 1 since zero is not + legitimate. + +JH/09 Bug 2274: Fix logging of cmdline args when starting in an unlinked cwd. + Previously this would segfault. + Exim version 4.91 -----------------