exim4_4.80-7+deb7u2_amd64.changes ACCEPTED into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Fri Mar 18 22:19:58 UTC 2016
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 12 Mar 2016 13:34:16 +0100
Source: exim4
Binary: exim4-base exim4-config exim4-daemon-light exim4 exim4-daemon-heavy exim4-daemon-custom eximon4 exim4-dbg exim4-daemon-light-dbg exim4-daemon-heavy-dbg exim4-daemon-custom-dbg exim4-dev
Architecture: source amd64 all
Version: 4.80-7+deb7u2
Distribution: wheezy-security
Urgency: high
Maintainer: Exim4 Maintainers <pkg-exim4-maintainers at lists.alioth.debian.org>
Changed-By: Andreas Metzler <ametzler at debian.org>
Description:
exim4 - metapackage to ease Exim MTA (v4) installation
exim4-base - support files for all Exim MTA (v4) packages
exim4-config - configuration for the Exim MTA (v4)
exim4-daemon-custom - custom Exim MTA (v4) daemon with locally set features
exim4-daemon-custom-dbg - debugging symbols for the Exim MTA (v4) packages
exim4-daemon-heavy - Exim MTA (v4) daemon with extended features, including exiscan-ac
exim4-daemon-heavy-dbg - debugging symbols for the Exim MTA "heavy" daemon
exim4-daemon-light - lightweight Exim MTA (v4) daemon
exim4-daemon-light-dbg - debugging symbols for the Exim MTA "light" daemon
exim4-dbg - debugging symbols for the Exim MTA (utilities)
exim4-dev - header files for the Exim MTA (v4) packages
eximon4 - monitor application for the Exim MTA (v4) (X11 interface)
Changes:
exim4 (4.80-7+deb7u2) wheezy-security; urgency=high
.
* 88_CVE-2016-1531.diff:
+ Fix CVE-2016-1531, a local privilege escalation issue when perl_startup
is used.
+ New options keep_environment/add_environment which are empty by default,
i.e. any subprocesses start in a clean (empty) environment.
+ -C requires an absolute path.
+ Exim changes it's working directory to / right after startup.
* Add macros MAIN_KEEP_ENVIRONMENT and MAIN_ADD_ENVIRONMENT to set the
new options. Set "keep_environment =" by default to avoid a runtime
warning. Bump exim4-config Breaks to exim4-daemon-* (<< 4.80-7+deb7u2).
* 89_01_only_warn_on_nonempty_environment.diff,
89_02_Store-the-initial-working-directory.diff: Upstream followups on the
CVE fix (Thanks, Heiko Schlittermann!):
+ Runtime warning is only generated if (and only if) keep_environment
is unset and environment is nonempty.
+ Store the initial working directory and make it available in the new
expansion variable $initial_cwd.
* Add NEWS entry to warn of potential breakage.
Checksums-Sha1:
fcb333a87b9f80d77470b776f035f183eee864eb 2803 exim4_4.80-7+deb7u2.dsc
ba9b78b9dfab48f45409ab7c1c94ad085347899d 1649827 exim4_4.80.orig.tar.bz2
79fa90069fa46087df66ea64f6e6232ca625927a 593330 exim4_4.80-7+deb7u2.debian.tar.gz
ed469594caf331c6c7b1ae1c22b8b144e2670eee 1041686 exim4-base_4.80-7+deb7u2_amd64.deb
61643953ddca2d96958f8eeaf105b0f504ac8921 212268 eximon4_4.80-7+deb7u2_amd64.deb
9af19b33f70d1655e8320e2eacbb8981abe3291f 656586 exim4-daemon-light_4.80-7+deb7u2_amd64.deb
3b962492dd6d23dc80fc2143588b56f0bac5ed38 716598 exim4-daemon-heavy_4.80-7+deb7u2_amd64.deb
40e44481a193088973500c4a8a4037006ce6376c 1249082 exim4-daemon-light-dbg_4.80-7+deb7u2_amd64.deb
e6d1be8cc4bbf18acc6d53b2982e7368782a2fe4 1400658 exim4-daemon-heavy-dbg_4.80-7+deb7u2_amd64.deb
1ad62d63351656108b0cf21dd3d81e5c73dfabb0 451762 exim4-dbg_4.80-7+deb7u2_amd64.deb
4433a9c5ed2ea1e48a1de084021951426fd36cbc 174528 exim4-dev_4.80-7+deb7u2_amd64.deb
9c86cbdcde3d914c9ad27a397830a5e3126f7e0e 478804 exim4-config_4.80-7+deb7u2_all.deb
62ddecc447bffe929ee874ad94cd8c17ab423e28 7788 exim4_4.80-7+deb7u2_all.deb
Checksums-Sha256:
9f6882283366ba52790cb8cee7d6e766df537fe00fbd6c47d3dd9c78612b0590 2803 exim4_4.80-7+deb7u2.dsc
787b6defd37fa75311737bcfc42e9e2b2cc62c5d027eed35bb7d800b2d9a0984 1649827 exim4_4.80.orig.tar.bz2
8a07cb3c49ab242b1ffc499fa7d445991fae0950d1b753bc7cda83d5b4271f1d 593330 exim4_4.80-7+deb7u2.debian.tar.gz
9302c2b8c6c6b71a75c4345ea10f564902465198e049fd562989f3882ecdc26c 1041686 exim4-base_4.80-7+deb7u2_amd64.deb
95892f6538bbd9aa6e72e03acad152824bcb42e0872e6f7c09f647f32e51d9d9 212268 eximon4_4.80-7+deb7u2_amd64.deb
8a62fce43174e3553b21924c5de917405700a7edf81c993f03aad5232713d435 656586 exim4-daemon-light_4.80-7+deb7u2_amd64.deb
dc15359f45680831722e44bf208ddd6f9bb0e1d271b7cee3d132da7b70edab97 716598 exim4-daemon-heavy_4.80-7+deb7u2_amd64.deb
fb48cc2a79444500fa5dcceb1cba2c1559283eeddde3f31502808be71e20f233 1249082 exim4-daemon-light-dbg_4.80-7+deb7u2_amd64.deb
54a8f21581a9870b656e4bb364b2988d52b52a97e3227608b21e2ea534bf9726 1400658 exim4-daemon-heavy-dbg_4.80-7+deb7u2_amd64.deb
ee62e5c607d67a0756afec10aa03abcbf63f577e708bbfd2fcab0d3933548bea 451762 exim4-dbg_4.80-7+deb7u2_amd64.deb
d5e8a946e78f1a6e30321535915bd27c41fff33029d5d4337c8a6e483652e6f2 174528 exim4-dev_4.80-7+deb7u2_amd64.deb
0ad964f1895a8549aeb018c86ff64f50e579fb409419d84158f8b3036acc0121 478804 exim4-config_4.80-7+deb7u2_all.deb
2727ce25b703fd5e5dca9cf8c30f694845b8a69138d6a4b0c1018d1dbc144081 7788 exim4_4.80-7+deb7u2_all.deb
Files:
e5053c4489ce684ebff708178ad3ee18 2803 mail standard exim4_4.80-7+deb7u2.dsc
de93a242e9e148de28d67056e5c1b34f 1649827 mail standard exim4_4.80.orig.tar.bz2
a4c23ef8d95628e2d449864770e41f79 593330 mail standard exim4_4.80-7+deb7u2.debian.tar.gz
67da1fe94bc0544e4300caa1e350fd57 1041686 mail standard exim4-base_4.80-7+deb7u2_amd64.deb
b758a737c15dd97c1e07509bef4281fb 212268 mail optional eximon4_4.80-7+deb7u2_amd64.deb
d10f4a519a09694a82f8adaa7175aa80 656586 mail standard exim4-daemon-light_4.80-7+deb7u2_amd64.deb
8154eda459783706654682669b26112c 716598 mail optional exim4-daemon-heavy_4.80-7+deb7u2_amd64.deb
035939910fab2abde90f5b914367cf49 1249082 debug extra exim4-daemon-light-dbg_4.80-7+deb7u2_amd64.deb
cfb68ceaa9986d705ad80089666c26f7 1400658 debug extra exim4-daemon-heavy-dbg_4.80-7+deb7u2_amd64.deb
02ff89351cbfdab0ec2090ac6f46b4f8 451762 debug extra exim4-dbg_4.80-7+deb7u2_amd64.deb
490ea14bd8ddec692c3ada1f76cb00c0 174528 mail extra exim4-dev_4.80-7+deb7u2_amd64.deb
769bf1fd1462976d5e3786505282b828 478804 mail standard exim4-config_4.80-7+deb7u2_all.deb
adbfa9ff4eca85f87203b2883d18c65b 7788 mail standard exim4_4.80-7+deb7u2_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQIcBAEBCgAGBQJW5bG7AAoJEKVPAYVDghSE08kP/i5aXie1qmGyvfG+ONd1tOVZ
u48ZtYkutCHBpyOsead1YEUqWKfatSPnWYm9nvnkt5vjBfjsRLXbHkzc/FsEDncF
PVIVmOmldWss9queQymggRonuywjV39p2zBBm5DtoIu85g+agim30+DBqRSmqFCb
zyAoVlpuuWmIWznt1CED0amRjbU3UnvgnVWJEylF1e4tKB4x4/YsHMJ18Kq/Zk+0
XkuzDLRuO3pQWa/GtXrpkzwRX7MQ4bjo0WCnx//zc1ldosuVDy4y/eJxtz8Qgqmy
oBPx0mzx/HKKrvxkzbDabkZLdy/zr9UJaBX6GAkq8FVEH/gBoNcxbXyqLkMt1cvz
x6jxzAgplIsYiPjUCckR+fyaO/FZePbXbemF4MNs3CHuZq585lXM/ndqtfvOKcFE
Bzn1JHj79nocoEC7ywjyyih98xbEgZmGmIFXqOkvmbAQh9148khA8/4XUvOdQe4g
bqh+K2pbAPclj9/0wo+Y6kFANvrjoYahLQKtVd8vVUlrATFOub1oBJYdS+oOkusd
0jSVWT01Qn83fWnLsUsEt7BqB/T8FNqyqv7xI9XCQITnckJC14AEE6zLSb4WTHlg
P3mZZUtgWi7xdAxw+GoBlDjzUQGLhDlObpgefNhB88L9BWEyboG4CB7nIDFT99BO
o8Kna42m0/E4wLCrxxeL
=+JLW
-----END PGP SIGNATURE-----
Thank you for your contribution to Debian.
More information about the Pkg-exim4-maintainers
mailing list