summaryrefslogtreecommitdiff
path: root/src
AgeCommit message (Expand)Author
2021-06-24deliverHeiko Schlittermann (HS12-RIPE)
2021-06-24pipeHeiko Schlittermann (HS12-RIPE)
2021-06-24autoreplyHeiko Schlittermann (HS12-RIPE)
2021-06-24rdaHeiko Schlittermann (HS12-RIPE)
2021-06-24parseHeiko Schlittermann (HS12-RIPE)
2021-06-24aclHeiko Schlittermann (HS12-RIPE)
2021-06-24dbstuffHeiko Schlittermann (HS12-RIPE)
2021-06-24searchHeiko Schlittermann (HS12-RIPE)
2021-06-24Introduce main config option allow_insecure_tainted_dataHeiko Schlittermann (HS12-RIPE)
2021-06-22GnuTLS: fix build with older GnuTLSJeremy Harris
2021-06-22TLS: as server, reject connections with ALPN indicating non-smtp useJeremy Harris
2021-06-21Compiler quieteningJeremy Harris
2021-06-19OpenSSL: on library versions too old to support session ticketsJeremy Harris
2021-06-17OpenSSL: fix verify-certs stack initializationJeremy Harris
2021-06-15hosts_require_heloJeremy Harris
2021-06-08Fix server creds cache invalidationJeremy Harris
2021-06-07compiler quieteningJeremy Harris
2021-06-07Re-fix non-Linux buildJeremy Harris
2021-06-06tidyingJeremy Harris
2021-06-06Fix non-Linux buildJeremy Harris
2021-06-06Observability: listen queue backlogJeremy Harris
2021-06-06Avoid rescanning listen select setJeremy Harris
2021-06-06Compute select fd_set outside daemon loopJeremy Harris
2021-06-05Fix SSL creds file watching on kevent platforms (BSDs) for symlinksJeremy Harris
2021-06-04DMARC: note unsupported library versions issueJeremy Harris
2021-06-04debug: fix openssl outputJeremy Harris
2021-06-03DKIM: under GnuTLS, permit weak algorithmsJeremy Harris
2021-05-28tidyingJeremy Harris
2021-05-28tidyingJeremy Harris
2021-05-28Logging: avoid pause during log-open under testsuiteJeremy Harris
2021-05-28Fix dmarc buildJeremy Harris
2021-05-27Fix BDAT issue for body w/o trailing CRLF (again Bug 1974)Heiko Schlittermann (HS12-RIPE)
2021-05-27rewrite: revert to unchecked result of parse_extract_address()Heiko Schlittermann (HS12-RIPE)
2021-05-27Honour the outcome of parse_extract_address(), testsuite 471Heiko Schlittermann (HS12-RIPE)
2021-05-27Update upgrade notes and source about use of seteuid()Heiko Schlittermann (HS12-RIPE)
2021-05-27CVE-2020-28007: Link attack in Exim's log directoryQualys Security Advisory
2021-05-27CVE-2020-28016: Heap out-of-bounds write in parse_fix_phrase()Heiko Schlittermann (HS12-RIPE)
2021-05-27SECURITY: Avoid modification of constant data in dkim handlingHeiko Schlittermann (HS12-RIPE)
2021-05-27SECURITY: Leave a clean smtp_out input buffer even in case of read errorHeiko Schlittermann (HS12-RIPE)
2021-05-27SECURITY: Always exit when LOG_PANIC_DIE is setQualys Security Advisory
2021-05-27CVE-2020-28012: Missing close-on-exec flag for privileged pipeQualys Security Advisory
2021-05-27CVE-2020-28024: Heap buffer underflow in smtp_ungetc()Qualys Security Advisory
2021-05-27CVE-2020-28009: Integer overflow in get_stdinput()Qualys Security Advisory
2021-05-27CVE-2020-28015+28021: New-line injection into spool header fileQualys Security Advisory
2021-05-27CVE-2020-28026: Line truncation and injection in spool_read_header()Heiko Schlittermann (HS12-RIPE)
2021-05-27CVE-2020-28022: Heap out-of-bounds read and write in extract_option()Heiko Schlittermann (HS12-RIPE)
2021-05-27CVE-2020-28017: Integer overflow in receive_add_recipient()Heiko Schlittermann (HS12-RIPE)
2021-05-27SECURITY: Refuse negative and large store allocationsHeiko Schlittermann (HS12-RIPE)
2021-05-27CVE-2020-28013: Heap buffer overflow in parse_fix_phrase()Heiko Schlittermann (HS12-RIPE)
2021-05-27CVE-2020-28011: Heap buffer overflow in queue_run()Qualys Security Advisory