From 1bd642c265dae5643f16d023879043b7576f66a9 Mon Sep 17 00:00:00 2001 From: Jeremy Harris Date: Fri, 11 May 2018 18:02:29 +0100 Subject: Content scanning: Fix locking on message spool files. Bug 2275 --- doc/doc-txt/ChangeLog | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'doc/doc-txt') diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog index d99b2684a..5ce54a24e 100644 --- a/doc/doc-txt/ChangeLog +++ b/doc/doc-txt/ChangeLog @@ -32,6 +32,14 @@ JH/05 Bug 2273: Cutthrough delivery left a window where the received messsage PP/01 Refuse to open a spool data file (*-D) if it's a symlink. No known attacks, no CVE, this is defensive hardening. +JH/06 Bug 2275: The MIME ACL unlocked the received message files early, and + a queue-runner could start a delivery while other operations were ongoing. + Cutthrough delivery was a common victim, resulting in duplicate delivery. + Found and investigated by Tim Stewart. Fix by using the open message data + file handle rather than opening another, and not locally closing it (which + releases a lock) for that case, while creating the temporary .eml format + file for the MIME ACL. Also applies to "regex" and "spam" ACL conditions. + Exim version 4.91 ----------------- -- cgit v1.2.3