From 0695aae1eb75b439862d0f7fbf099b5d08f55af0 Mon Sep 17 00:00:00 2001 From: Phil Pennock Date: Thu, 29 Oct 2020 21:48:05 -0400 Subject: SECURITY: Avoid integer overflow on too many recipients (cherry picked from commit 323ff55e67b44e95f9d3cfaba155e385aa33c4bd) (cherry picked from commit 3a54fcd1e303bf1cc49beca7ceac35d7448860a9) --- doc/doc-txt/ChangeLog | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'doc') diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog index 89a60e757..3d0e638d2 100644 --- a/doc/doc-txt/ChangeLog +++ b/doc/doc-txt/ChangeLog @@ -280,6 +280,11 @@ PP/07 Refuse to allocate too little memory, block negative/zero allocations. PP/08 Change default for recipients_max from unlimited to 50,000. +PP/09 Fix security issue with too many recipients on a message (to remove a + known security problem if someone does set recipients_max to unlimited, + or if local additions add to the recipient list). + Fixes CVE-2020-RCPTL reported by Qualys. + Exim version 4.94 ----------------- -- cgit v1.2.3