The 6.3.22 release of fetchmail is available

Matthias Andree <[email protected]> Thu, 30 Aug 2012 00:32:08 +0200
Newsgroups gmane.mail.fetchmail.announce
Message-ID <[email protected]>
--===============1795986529949348890==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="SLDf9lqlvOQaIe6s"
Content-Disposition: inline


--SLDf9lqlvOQaIe6s
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

The 6.3.22 release of fetchmail is now available at the usual locations,
including <http://developer.berlios.de/projects/fetchmail>.

The source archive is available at:
<http://developer.berlios.de/projects/fetchmail/fetchmail-6.3.22.tar.bz2>

or if you prefer XZ archives:
<http://developer.berlios.de/projects/fetchmail/fetchmail-6.3.22.tar.xz>

Add .asc to the file names to obtain detached GnuPG signatures.

Here are the release notes:

fetchmail-6.3.22 (released 2012-08-29, 26077 LoC):

# SECURITY FIXES
* for CVE-2012-3482:
  NTLM: fetchmail mistook an error message that the server sent in response=
 to
  an NTLM request for protocol exchange, tried to decode it, and crashed wh=
ile
  reading from a bad memory location.
  Also, with a carefully crafted NTLM challenge packet sent from the server=
, it
  would be possible that fetchmail conveyed confidential data not meant for=
 the
  server through the NTLM response packet.
  Fix: Detect base64 decoding errors, validate the NTLM challenge, and abort
  NTLM authentication in case of error.
  See fetchmail-SA-2012-02.txt for further details.
  Reported by J. Porter Clark.

* for CVE-2011-3389:
  SSL/TLS (wrapped and STARTTLS): fetchmail used to disable a countermeasur=
e=20
  against a certain kind of attack against cipher block chaining initializa=
tion=20
  vectors (SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS).
  Whether this creates an exploitable situation, depends on the server and =
the=20
  negotiated ciphers.
  As a precaution, fetchmail 6.3.22 enables the countermeasure, by clearing=
=20
  SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS.

  NOTE that this can cause connections to certain non-conforming servers to=
=20
  fail, in which case you can set the environment variable=20
  FETCHMAIL_DISABLE_CBC_IV_COUNTERMEASURE to any non-empty value when start=
ing
  fetchmail to re-instate the compatibility option at the expense of securi=
ty.

  Reported by Apple Product Security.

  For technical details, refer to <http://www.openssl.org/~bodo/tls-cbc.txt=
>.
  See fetchmail-SA-2012-01.txt for further details.

# BUG FIX
* The Server certificate: message in verbose mode now appears on stdout lik=
e the
  remainder of the output. Reported by Henry Jensen, to fix Debian Bug #639=
807.

* The GSSAPI-related autoconf code now matches gssapi.c better, and uses
  a different check to look for GSS_C_NT_HOSTBASED_SERVICE.
  This fixes the GSSAPI-enabled build on NetBSD 6 Beta.

# CHANGES
* On systems where SSLv2_client_method isn't defined in OpenSSL (such as
  newer Debian, and Ubuntu starting with 11.10 oneiric ocelot), don't
  reference it (to fix the build) and if configured, print a run-time error=
=20
  that the OS does not support SSLv2. Fixes Debian Bug #622054,=20
  but note that that bug report has a more thorough patch that does away wi=
th
  SSLv2 altogether.

* The security and errata notices fetchmail-{EN,SA}-20??-??.txt are now
  under the more relaxed CC BY-ND 3.0 license (the noncommercial clause
  was dropped). The Creative Commons address was updated.

* The Python-related Makefile.am parts were simplified to avoid an automake
  1.11.X bug around noinst_PYTHON, Automake Bug #10995.

* Configuring fetchmail without SSL now triggers a configure warning,
  and asks the user to consider running configure --with-ssl.

# WORKAROUND
* Some servers, notably Zimbra, return A1234 987 FETCH () in response to
  a header request, in the face of message corruption.  fetchmail now treats
  these as temporary errors. Report and Patch by Mikulas Patocka, Red Hat.

* Some servers, notably Microsoft Exchange, return "A0009 OK FETCH complete=
d."
  without any header in response to a header request for meeting reminder
  messages (with a "meeting.ics" attachment). fetchmail now treats these as
  transient errors.  Report by John Connett, Patch by Sunil Shetye.

# TRANSLATION UPDATES
* [cs]    Czech, by Petr Pisar
* [de]    German
* [fr]    French, by Fr=C3=A9d=C3=A9ric Marchal
* [ja]    Japanese, by Takeshi Hamasaki
* [pl]    Polish, by Jakub Bogusz
* [sv]    Swedish, by G=C3=B6ran Uddeborg --- NEW TRANSLATION - Thank you!
* [vi]    Vietnamese, by Tr=E1=BA=A7n Ng=E1=BB=8Dc Qu=C3=A2n

# KNOWN BUGS AND WORKAROUNDS
  (This section floats upwards through the NEWS file so it stays with the
  current release information)
* Fetchmail does not handle messages without Message-ID header well
  (See sourceforge.net bug #780933)
* BSMTP is mostly untested and errors can cause corrupt output.
* Sun Workshop 6 (SPARC) is known to miscompile the configuration file lexe=
r in
  64-bit mode.  Either compile 32-bit code or use GCC to compile 64-bit
  fetchmail.  Note that fetchmail doesn't take advantage of 64-bit code,
  so compiling 32-bit SPARC code should not cause any difficulties.
* Fetchmail does not track pending deletes across crashes.
* The command line interface is sometimes a bit stubborn, for instance,
  fetchmail -s doesn't work with a daemon running.
* Linux systems may return duplicates of an IP address in some circumstance=
s if
  no or no global IPv6 addresses are configured.
  (No workaround. Ubuntu Bug#582585, Novell Bug#606980.)
* Kerberos 5 may be broken, particularly on Heimdal, and provide bogus error
  messages. This will not be fixed, because the maintainer has no Kerberos 5
  server to test against. Use GSSAPI.


--SLDf9lqlvOQaIe6s
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAlA+mGgACgkQvmGDOQUufZW/wQCeMLJIyoTXnZhBBa3J5ub1Cz4T
9ngAoIkwmu5l7ZhHrBxjM0Me1RGj9gjw
=qI0q
-----END PGP SIGNATURE-----

--SLDf9lqlvOQaIe6s--

--===============1795986529949348890==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
fetchmail-announce mailing list
[email protected]
https://lists.berlios.de/mailman/listinfo/fetchmail-announce
--===============1795986529949348890==--