sendmail 8.12.10.Beta2 available

Claus Assmann <[email protected]> Tue, 1 Jul 2003 08:10:12 -0700
Newsgroups gmane.mail.sendmail.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----

Sendmail, Inc., and the Sendmail Consortium announce the availability
of sendmail 8.12.10.Beta2.  This beta version fixes some bugs that
were uncovered by the changes made in 8.12.9.  Most of these bugs
are minor and have workarounds.  Unless you experience actually
one of the problems listed below there is no need to upgrade.

Please send bug reports to [email protected] as usual.

The version can be found at

ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.10.Beta2.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.10.Beta2.tar.gz.sig

and the usual mirror sites.

MD5 signatures:

3f302b45edd11bb934e76a9706e57afb sendmail.8.12.10.Beta2.tar.gz
f89cef02390bd1ae7e1fa977f0f2adcb sendmail.8.12.10.Beta2.tar.gz.sig

The PGP signature was created using the Sendmail Signing Key/2003,
available on the web site (http://www.sendmail.org/) or on the
public key servers.

Since sendmail 8.11 and later includes hooks to cryptography, the
following information from OpenSSL applies to sendmail as well.

   PLEASE REMEMBER THAT EXPORT/IMPORT AND/OR USE OF STRONG CRYPTOGRAPHY
   SOFTWARE, PROVIDING CRYPTOGRAPHY HOOKS OR EVEN JUST COMMUNICATING
   TECHNICAL DETAILS ABOUT CRYPTOGRAPHY SOFTWARE IS ILLEGAL IN SOME
   PARTS OF THE WORLD.  SO, WHEN YOU IMPORT THIS PACKAGE TO YOUR
   COUNTRY, RE-DISTRIBUTE IT FROM THERE OR EVEN JUST EMAIL TECHNICAL
   SUGGESTIONS OR EVEN SOURCE PATCHES TO THE AUTHOR OR OTHER PEOPLE
   YOU ARE STRONGLY ADVISED TO PAY CLOSE ATTENTION TO ANY EXPORT/IMPORT
   AND/OR USE LAWS WHICH APPLY TO YOU. THE AUTHORS ARE NOT LIABLE FOR
   ANY VIOLATIONS YOU MAKE HERE. SO BE CAREFUL, IT IS YOUR RESPONSIBILITY.


			SENDMAIL RELEASE NOTES
      $Id: RELEASE_NOTES,v 8.1340.2.153 2003/06/23 21:09:25 ca Exp $


This listing shows the version of the sendmail binary, the version
of the sendmail configuration files, the date of release, and a
summary of the changes in that release.

8.12.10/8.12.10	200x/xx/xx
	Fix a potential buffer overflow in ruleset parsing.  This problem
		is not exploitable in the default sendmail configuration;
		only if non-standard rulesets recipient (2), final (4), or
		mailer-specific envelope recipients rulesets are used then
		a problem may occur.  Problem noted by Timo Sirainen.
	Accept 0 (and 0/0) as valid input for set MaxMimeHeaderLength.
		Problem noted by Thomas Schulz.
	Add several checks to avoid (theoretical) buffer over/underflows.
	Properly count message size when performing 7->8 or 8->7 bit MIME
		conversions.  Problem noted by Werner Wiethege.
	Properly compute message priority based on size of entire message,
		not just header.  Problem noted by Axel Holscher.
	Reset SevenBitInput to its configured value between SMTP
		transactions for broken clients which do not properly
		announce 8 bit data.  Problem noted by Stefan Roehrich.
	Set {addr_type} during queue runs when processing recipients.
		Based on patch from Arne Jansen.
	Add ':' to the allowed character list for bogus HELO/EHLO
		checking.  It is used for IPv6 domain literals.  Patch from
		Iwaizako Takahiro of FreeBit Co., Ltd.
	Reset SASL connection context after a failed authentication attempt.
		Based on patch from Rob Siemborski of CMU.
	Check Berkeley DB compile time version against run time version
		to make sure they match.
	CONFIG: Use specified SMTP error code in mailertable entries which
		lack a DSN, i.e., "error:### Text".  Problem noted by
		Craig Hunt.
	CONTRIB: Better handling of temporary filenames for doublebounce.pl
		and expn.pl to avoid file overwrites, etc.  Patches from
		Richard A. Nelson of Debian and Paul Szabo.
	MAIL.LOCAL: Fix obscure race condition that could lead to an
		improper mailbox truncation if close() fails after the
		mailbox is fsync()'ed and a new message is delivered
		after the close() and before the truncate().
	Portability:
		Port for AIX 5.2.  Thanks to Steve Hubert of University
			of Washington for providing access to a computer
			with AIX 5.2.
		Allow for custom definition of SMRSH_CMDDIR and SMRSH_PATH
			on all operating systems.  Patch from Robert Harker
			of Harker Systems.
	Added Files:
		devtools/OS/AIX.5.2

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (OpenBSD)

iQCVAwUBPwGiAiGD4bE5bweJAQHV7QP9FiAG1olpkG2MfxKP6dfwDPUi/FwrUcnf
iKCXlQK+o8Rw+bg3aqG1nb8Xzh63KausMlxpnBGPrB6bqBQ4iXfSOiX+cWmC19jT
ihI/7uiB/BDwpTrf2RFqLDyzyWQVtFrXEPCQ7U7VZhX7xruyOtY3RflrJKFQviPV
wERTK9E0T20=
=0HOO
-----END PGP SIGNATURE-----