summaryrefslogtreecommitdiff
path: root/doc
diff options
context:
space:
mode:
authorJeremy Harris <jgh146exb@wizmail.org>2023-09-01 11:44:32 +0100
committerJeremy Harris <jgh146exb@wizmail.org>2023-09-01 11:44:32 +0100
commit9b810c775c6e9dd1f8a87a743b943b465a1ca5a1 (patch)
treed1972edb4719307adfb2361895e0faa19dcd2840 /doc
parent91474c3e8619022e87b3d658017aeabd7273a7e3 (diff)
Taint: track SASL auth intermediate inputs
Diffstat (limited to 'doc')
-rw-r--r--doc/doc-txt/ChangeLog5
1 files changed, 5 insertions, 0 deletions
diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog
index f2802d2fb..b1b79c240 100644
--- a/doc/doc-txt/ChangeLog
+++ b/doc/doc-txt/ChangeLog
@@ -185,6 +185,11 @@ JH/37 Bug 3016: Avoid sending DSN when message was accepted under fakereject
or fakedefer. Previously the sender could discover that the message
had in fact been accepted.
+JH/38 Taint-track intermediate values from the peer in multi-stage authentation
+ sequences. Previously the input was not noted as being tainted; notably
+ this resulted in behaviour of LOGIN vs. PLAIN being inconsistent under
+ bad coding of authenticators.
+
Exim version 4.96
-----------------