Page MenuHomeFreeBSD

Update mail/postfixadmin to 3.0.2 (security fix)
ClosedPublic

Authored by krion on Feb 10 2017, 11:56 AM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Nov 29, 1:36 AM
Unknown Object (File)
Thu, Nov 27, 10:35 AM
Unknown Object (File)
Tue, Nov 25, 8:57 PM
Unknown Object (File)
Sun, Nov 23, 11:50 AM
Unknown Object (File)
Mon, Nov 17, 1:42 PM
Unknown Object (File)
Sun, Nov 16, 12:28 AM
Unknown Object (File)
Wed, Nov 12, 5:15 PM
Unknown Object (File)
Wed, Nov 12, 8:35 AM
Subscribers
None

Details

Summary

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=216932

Maintainer approved.

The most important reason for the release was a SECURITY FIX: don't allow to
delete protected aliases (CVE-2017-5930, PR#23). Thanks to Janfred @github for
the report and the pull request!

Besides that, the following non-security bugs were fixed:

  • fix VacationHandler for PostgreSQL
  • AliasHandler: restrict mailbox subquery to allowed and specified domains to improve performance on setups with lots of mailboxes
  • allow switching between dovecot: password schemes while still accepting passwords hashed using the previous dovecot: scheme
  • FetchmailHandler: use a valid date as default for 'date'
  • fix date formatting in non-english languages when using PostgreSQL
  • various small fixes

Diff Detail

Repository
rP FreeBSD ports repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

krion retitled this revision from to Update mail/postfixadmin to 3.0.2 (security fix).
krion updated this object.
krion edited the test plan for this revision. (Show Details)
krion added reviewers: mat, fjoe.
mat edited edge metadata.
This revision is now accepted and ready to land.Feb 10 2017, 5:19 PM
This revision was automatically updated to reflect the committed changes.