Branches for Warty

Name Status Last Modified Last Commit
lp:ubuntu/warty/exim4 1 Development 2009-06-24 03:11:35 UTC
2. * Syncing package from Debian. * Reve...

Author: Fabio Massimo Di Nitto
Revision Date: 2004-08-12 12:22:48 UTC

* Syncing package from Debian.
* Revert Build-Dep to libgnutls10-dev.

lp:ubuntu/warty-security/exim4 1 Development 2009-06-24 03:11:41 UTC
3. * SECURITY UPDATE: fix several buffer...

Author: Martin Pitt
Revision Date: 2005-01-07 12:18:05 UTC

* SECURITY UPDATE: fix several buffer overflows
* Added patch 66_can2005-0021_can2005-0022.dpatch (backported from Hoary/Sid
  version 4.34-10):
  - src/host.c, host_aton(): check input IPv6 address length and die if it
    is too long (CAN-2005-0021); input to this function is supposed to be
    checked already, but there was at least one case where this function got
    an unchecked value, so this is a fallback test
  - src/lookups/dnsdb.c, dnsdb_find(): check that PTR record value is really
    an IPv6 address (to avoid ungraceful die in later check in host_aton()
    function)
  - src/auths/auth-spa.[hc], spa_base64_to_bits(): add an output length
    buffer argument, check output buffer length while writing it to avoid
    overflow (CAN-2005-0022)
* References:
  CAN-2005-0021
  CAN-2005-0022
  http://www.exim.org/mail-archives/exim-announce/2005/msg00000.html

12 of 2 results