Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 351204 - exim version bump 4.73
Summary: exim version bump 4.73
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Fabian Groffen
URL: http://exim.org
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-01-09 12:21 UTC by Thomas Stein
Modified: 2011-01-10 18:46 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Stein 2011-01-09 12:21:31 UTC
from Changelog:

DW/22 Bugzilla 1044: CVE-2010-4345 - partial fix: restrict default behaviour
      of CONFIGURE_OWNER and CONFIGURE_GROUP options to no longer allow a
      configuration file which is writeable by the Exim user or group.

DW/23 Bugzilla 1044: CVE-2010-4345 - part two: extend checks for writeability
      of configuration files to cover files specified with the -C option if
      they are going to be used with root privileges, not just the default
      configuration file.

DW/24 Bugzilla 1044: CVE-2010-4345 - part three: remove ALT_CONFIG_ROOT_ONLY
      option (effectively making it always true).

Reproducible: Always
Comment 1 Justin Lecher (RETIRED) gentoo-dev 2011-01-09 14:58:08 UTC
Thanks for the version bump notice. Assigning to maintainer
Comment 2 Fabian Groffen gentoo-dev 2011-01-10 14:58:31 UTC
Thanks, it's on my local tree, needs some verification before I commit it
Comment 3 Fabian Groffen gentoo-dev 2011-01-10 18:46:26 UTC
committed, thanks