From cd25e41d2d044556e024f0292a17c5ec3cc7987b Mon Sep 17 00:00:00 2001 From: David Woodhouse Date: Sat, 11 Dec 2010 23:39:54 +0000 Subject: Remove ALT_CONFIG_ROOT_ONLY build option, effectively making it always true. We *never* want the Exim user to be able to specify arbitrary configuration files. Don't let them build it that way. (Bug 1044, CVE-2010-4345) --- doc/doc-txt/ChangeLog | 3 +++ 1 file changed, 3 insertions(+) (limited to 'doc/doc-txt') diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog index 0063c6be0..afc854e44 100644 --- a/doc/doc-txt/ChangeLog +++ b/doc/doc-txt/ChangeLog @@ -83,6 +83,9 @@ DW/23 Bugzilla 1044: CVE-2010-4345 - part two: extend checks for writeability they are going to be used with root privileges, not just the default configuration file. +DW/24 Bugzilla 1044: CVE-2010-4345 - part three: remove ALT_CONFIG_ROOT_ONLY + option (effectively making it always true). + Exim version 4.72 ----------------- -- cgit v1.2.3