summaryrefslogtreecommitdiff
path: root/doc/doc-txt
diff options
context:
space:
mode:
authorJeremy Harris <jgh146exb@wizmail.org>2018-05-11 18:02:29 +0100
committerJeremy Harris <jgh146exb@wizmail.org>2018-05-16 21:17:18 +0100
commit1bd642c265dae5643f16d023879043b7576f66a9 (patch)
tree0aa9c08d5d80d50bfa6060801b320fb2771eed01 /doc/doc-txt
parent85defcf0e9e4187107b8a1a5138ef9590ac3892c (diff)
Content scanning: Fix locking on message spool files. Bug 2275
Diffstat (limited to 'doc/doc-txt')
-rw-r--r--doc/doc-txt/ChangeLog8
1 files changed, 8 insertions, 0 deletions
diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog
index d99b2684a..5ce54a24e 100644
--- a/doc/doc-txt/ChangeLog
+++ b/doc/doc-txt/ChangeLog
@@ -32,6 +32,14 @@ JH/05 Bug 2273: Cutthrough delivery left a window where the received messsage
PP/01 Refuse to open a spool data file (*-D) if it's a symlink.
No known attacks, no CVE, this is defensive hardening.
+JH/06 Bug 2275: The MIME ACL unlocked the received message files early, and
+ a queue-runner could start a delivery while other operations were ongoing.
+ Cutthrough delivery was a common victim, resulting in duplicate delivery.
+ Found and investigated by Tim Stewart. Fix by using the open message data
+ file handle rather than opening another, and not locally closing it (which
+ releases a lock) for that case, while creating the temporary .eml format
+ file for the MIME ACL. Also applies to "regex" and "spam" ACL conditions.
+
Exim version 4.91
-----------------