diffstat of debian/ for exim4_4.92-4 exim4_4.92-4ubuntu1 changelog | 637 ++++++++++++++++++++++++++++++++++++++++++ control | 6 patches/fix_smtp_banner.patch | 53 +++ patches/series | 1 4 files changed, 695 insertions(+), 2 deletions(-) diff -Nru exim4-4.92/debian/changelog exim4-4.92/debian/changelog --- exim4-4.92/debian/changelog 2019-03-22 06:15:20.000000000 +0000 +++ exim4-4.92/debian/changelog 2019-03-25 11:02:33.000000000 +0000 @@ -1,3 +1,12 @@ +exim4 (4.92-4ubuntu1) disco; urgency=medium + + * Merge with Debian unstable (LP: #1821339). Remaining changes: + * Show Ubuntu distribution in SMTP banner + - Build-Depends on lsb-release to detect Distribution. + - d/p/fix_smtp_banner.patch: Show Ubuntu distribution in SMTP banner. + + -- Karl Stenerud Mon, 25 Mar 2019 12:02:33 +0100 + exim4 (4.92-4) unstable; urgency=medium * Another patch from exim-4.92+fixes branch: @@ -16,6 +25,15 @@ -- Andreas Metzler Wed, 20 Mar 2019 17:01:29 +0100 +exim4 (4.92-2ubuntu1) disco; urgency=medium + + * Merge with Debian unstable (LP: #1818444). Remaining changes: + - Show Ubuntu distribution in SMTP banner + + Build-Depends on lsb-release to detect Distribution. + + d/p/fix_smtp_banner.patch: Show Ubuntu distribution in SMTP banner. + + -- Karl Stenerud Tue, 05 Mar 2019 10:55:48 +0100 + exim4 (4.92-2) unstable; urgency=medium * Upload to unstable. @@ -72,6 +90,21 @@ -- Andreas Metzler Sun, 20 Jan 2019 17:52:39 +0100 +exim4 (4.92~RC4-2ubuntu2) disco; urgency=medium + + * No-change rebuild against libmysqlclient21 + + -- Steve Langasek Fri, 01 Feb 2019 16:57:54 +0000 + +exim4 (4.92~RC4-2ubuntu1) disco; urgency=medium + + * Merge with Debian unstable (LP: #1811095). Remaining changes: + - Show Ubuntu distribution in SMTP banner + + Build-Depends on lsb-release to detect Distribution. + + d/p/fix_smtp_banner.patch: Show Ubuntu distribution in SMTP banner. + + -- Karl Stenerud Thu, 10 Jan 2019 16:41:45 +0100 + exim4 (4.92~RC4-2) unstable; urgency=medium * Upload to unstable. @@ -165,6 +198,22 @@ -- Andreas Metzler Sun, 26 Aug 2018 11:33:15 +0200 +exim4 (4.91-6ubuntu2) disco; urgency=medium + + * No-change rebuild for the perl 5.28 transition. + + -- Adam Conrad Fri, 02 Nov 2018 18:08:13 -0600 + +exim4 (4.91-6ubuntu1) cosmic; urgency=medium + + * Merge with Debian unstable. Remaining changes: + - Show Ubuntu distribution in SMTP banner + + Build-Depends on lsb-release to detect Distribution. + + d/p/fix_smtp_banner.patch: Show Ubuntu distribution in SMTP banner. + [DEP3 header updated to indicate it has been forwarded to Debian] + + -- Andreas Hasenack Mon, 30 Jul 2018 15:35:06 -0300 + exim4 (4.91-6) unstable; urgency=low * Update from exim-4_91+fixes branch: @@ -176,6 +225,16 @@ -- Andreas Metzler Fri, 20 Jul 2018 11:21:24 +0200 +exim4 (4.91-5ubuntu1) cosmic; urgency=medium + + * Merge with Debian unstable. Remaining changes: + - Show Ubuntu distribution in SMTP banner + - Build-Depends on lsb-release to detect Distribution. + - d/p/fix_smtp_banner.patch: Show Ubuntu distribution in SMTP banner. + [DEP3 header updated to indicate it has been forwarded to Debian] + + -- Andreas Hasenack Tue, 03 Jul 2018 11:13:08 -0300 + exim4 (4.91-5) unstable; urgency=medium * Update from exim-4_91+fixes branch: @@ -185,6 +244,15 @@ -- Andreas Metzler Sat, 09 Jun 2018 18:10:39 +0200 +exim4 (4.91-4ubuntu1) cosmic; urgency=medium + + * Merge from Debian testing, Remaining changes: + - Show Ubuntu distribution in SMTP banner + - Build-Depends on lsb-release to detect Distribution. + - d/p/fix_smtp_banner.patch: Show Ubuntu distribution in SMTP banner. + + -- Christian Ehrhardt Wed, 30 May 2018 12:46:14 +0200 + exim4 (4.91-4) unstable; urgency=medium * Update from exim-4_91+fixes branch: @@ -303,6 +371,15 @@ -- Andreas Metzler Sat, 10 Mar 2018 14:25:51 +0100 +exim4 (4.90.1-1ubuntu1) bionic; urgency=medium + + * Merge from Debian testing, Remaining changes: + - Show Ubuntu distribution in SMTP banner + - Build-Depends on lsb-release to detect Distribution. + - d/p/fix_smtp_banner.patch: Show Ubuntu distribution in SMTP banner. + + -- Christian Ehrhardt Wed, 14 Feb 2018 17:01:14 +0100 + exim4 (4.90.1-1) unstable; urgency=high * New upstream version, fixing CVE-2018-6789. Closes: #890000 @@ -497,6 +574,15 @@ -- Andreas Metzler Sat, 25 Nov 2017 11:43:24 +0100 +exim4 (4.89-9ubuntu1) bionic; urgency=medium + + * Merge from Debian unstable, Remaining changes: + - Show Ubuntu distribution in SMTP banner + - Build-Depends on lsb-release to detect Distribution. + - d/p/fix_smtp_banner.patch: Show Ubuntu distribution in SMTP banner. + + -- Christian Ehrhardt Thu, 16 Nov 2017 10:02:23 +0100 + exim4 (4.89-9) unstable; urgency=medium * Upload to unstable. @@ -539,6 +625,42 @@ -- Andreas Metzler Sat, 09 Sep 2017 15:29:39 +0200 +exim4 (4.89-5ubuntu1.3) artful-security; urgency=medium + + * SECURITY UPDATE: Buffer overflow in base64d() + - debian/patches/CVE-2018-6789.patch: fix overflow in src/base64.c. + - CVE-2018-6789 + + -- Marc Deslauriers Sat, 10 Feb 2018 14:12:27 -0500 + +exim4 (4.89-5ubuntu1.2) artful-security; urgency=medium + + * SECURITY UPDATE: stack-exhaustion remote DoS + - debian/patches/CVE-2017-16944.patch: do not treat the first lonely + dot special in src/receive.c, src/smtp_in.c. + - CVE-2017-16944 + + -- Marc Deslauriers Wed, 29 Nov 2017 08:59:31 -0500 + +exim4 (4.89-5ubuntu1.1) artful-security; urgency=medium + + * SECURITY UPDATE: remote code execution via use-after-free + - debian/patches/CVE-2017-16943.patch: avoid release of store if there + have been later allocations in src/receive.c. + - CVE-2017-16943 + + -- Marc Deslauriers Mon, 27 Nov 2017 07:37:47 -0500 + +exim4 (4.89-5ubuntu1) artful; urgency=medium + + * Merge from Debian testing. + Remaining changes: + - Show Ubuntu distribution in SMTP banner + - Build-Depends on lsb-release to detect Distribution. + - d/p/fix_smtp_banner.patch: Show Ubuntu distribution in SMTP banner. + + -- Christian Ehrhardt Wed, 16 Aug 2017 15:42:47 +0200 + exim4 (4.89-5) unstable; urgency=medium * Update to exim-4_89+fixes branch: @@ -583,6 +705,20 @@ -- Andreas Metzler Sat, 15 Jul 2017 12:46:16 +0200 +exim4 (4.89-3ubuntu2) artful; urgency=medium + + * No-change rebuild for perl 5.26.0. + + -- Matthias Klose Wed, 26 Jul 2017 20:02:24 +0000 + +exim4 (4.89-3ubuntu1) artful; urgency=medium + + * Merge from Debian. Remaining changes: + - Show Ubuntu distribution in SMTP banner. + - Build-Depends on lsb-release (needed for the Ubuntu SMTP banner patch) + + -- Marc Deslauriers Tue, 27 Jun 2017 10:20:42 -0400 + exim4 (4.89-3) unstable; urgency=high * Re-upload to unstable. @@ -595,6 +731,15 @@ -- Wed, 14 Jun 2017 07:03:07 +0200 +exim4 (4.89-2ubuntu1) artful; urgency=medium + + * Merge from Debian testing. + Remaining changes: + + Show Ubuntu distribution in SMTP banner. + + Build-Depends on lsb-release (needed for the Ubuntu SMTP banner patch) + + -- Christian Ehrhardt Thu, 01 Jun 2017 11:58:00 +0200 + exim4 (4.89-2) unstable; urgency=medium * Revert addition of header "# pidfile: /var/run/exim4/exim.pid" to @@ -686,6 +831,17 @@ -- Andreas Metzler Tue, 31 Jan 2017 19:52:50 +0100 +exim4 (4.88-5ubuntu1) zesty; urgency=medium + + * Merge from Debian unstable. + Version 4.88 fixes CVE-2016-9963 (LP: #1654750) and symlink + local root escalation (LP: #1580454) + Remaining changes: + + Show Ubuntu distribution in SMTP banner. + + Build-Depends on lsb-release (needed for the Ubuntu SMTP banner patch) + + -- Christian Ehrhardt Tue, 24 Jan 2017 10:15:09 +0100 + exim4 (4.88-5) unstable; urgency=medium * 78_Disable-chunking-BDAT-by-default.patch: Change default value of main @@ -838,6 +994,20 @@ -- Andreas Metzler Sun, 25 Sep 2016 15:44:00 +0200 +exim4 (4.87-3ubuntu2) zesty; urgency=medium + + * No-change rebuild for perl 5.24 transition + + -- Iain Lane Mon, 24 Oct 2016 10:08:10 +0100 + +exim4 (4.87-3ubuntu1) yakkety; urgency=medium + + * Merge from Debian unstable. Remaining changes: + + Show Ubuntu distribution in SMTP banner. + + Build-Depends on lsb-release (needed for the Ubuntu SMTP banner patch) + + -- Christian Ehrhardt Tue, 26 Jul 2016 13:30:09 +0200 + exim4 (4.87-3) unstable; urgency=medium * Pull multiple patches from upstream GIT: @@ -1011,6 +1181,48 @@ -- Andreas Metzler Fri, 11 Dec 2015 20:15:30 +0100 +exim4 (4.86.2-2ubuntu2.3) xenial-security; urgency=medium + + * SECURITY UPDATE: Buffer overflow in base64d() + - debian/patches/CVE-2018-6789.patch: fix overflow in + src/auths/b64decode.c. + - CVE-2018-6789 + + -- Marc Deslauriers Sat, 10 Feb 2018 14:18:40 -0500 + +exim4 (4.86.2-2ubuntu2.2) xenial-security; urgency=medium + + * SECURITY UPDATE: memory leak + - debian/patches/93_CVE-2017-1000368.patch: free -p argument if + allocation was required. + - CVE-2017-1000368 + + -- Steve Beattie Fri, 02 Jun 2017 22:07:28 -0700 + +exim4 (4.86.2-2ubuntu2.1) xenial-security; urgency=medium + + * SECURITY UPDATE: DKIM information leakage + - debian/patches/CVE-2016-9963.patch: fix information leakage in + src/dkim.c, src/transports/smtp.c. + - CVE-2016-9963 + + -- Marc Deslauriers Thu, 05 Jan 2017 08:29:10 -0500 + +exim4 (4.86.2-2ubuntu2) xenial; urgency=medium + + * Rebuild against libmysqlclient20. + + -- Robie Basak Tue, 05 Apr 2016 12:21:41 +0000 + +exim4 (4.86.2-2ubuntu1) xenial; urgency=medium + + * Merge from Debian unstable. Remaining changes: + - debian.control, debian/patches/fix_smtp_banner.patch + + Show Ubuntu distribution in SMTP banner. + + Build-Depends on lsb-release. + + -- Marc Deslauriers Tue, 15 Mar 2016 11:56:18 -0400 + exim4 (4.86.2-2) unstable; urgency=high * Bump exim4-config Breaks to exim4-daemon-* (<< 4.86.2). Closes: #816790 @@ -1032,6 +1244,27 @@ -- Andreas Metzler Tue, 01 Mar 2016 19:34:39 +0100 +exim4 (4.86-7ubuntu3) xenial; urgency=medium + + * No-change rebuild for gnutls transition. + + -- Matthias Klose Wed, 17 Feb 2016 22:40:56 +0000 + +exim4 (4.86-7ubuntu2) xenial; urgency=medium + + * Rebuild for Perl 5.22.1. + + -- Colin Watson Fri, 18 Dec 2015 10:30:54 +0000 + +exim4 (4.86-7ubuntu1) xenial; urgency=medium + + * Merge from Debian unstable. Remaining changes: + - debian.control, debian/patches/fix_smtp_banner.patch + + Show Ubuntu distribution in SMTP banner. + + Build-Depends on lsb-release. + + -- Pierre-André MOREY Mon, 14 Dec 2015 14:23:51 +0100 + exim4 (4.86-7) unstable; urgency=medium * Allow arch-indep build (dpkg-buildpackage -A). Closes: #806023 @@ -1082,6 +1315,15 @@ -- Andreas Metzler Sat, 17 Oct 2015 15:01:01 +0200 +exim4 (4.86-3ubuntu1) wily; urgency=medium + + * Merge from Debian unstable. (LP: #1485369) Remaining changes: + - debian/control, debian/patches/fix_smtp_banner.patch: + + Show Ubuntu distribution in SMTP banner. + + Build-Depends on lsb-release. + + -- Artur Rona Thu, 17 Sep 2015 13:18:20 +0100 + exim4 (4.86-3) unstable; urgency=medium * Pull three patches from upstream git: @@ -1122,6 +1364,15 @@ -- Andreas Metzler Sat, 18 Jul 2015 11:46:11 +0200 +exim4 (4.86~RC4-2ubuntu1) wily; urgency=low + + * Merge from Debian unstable. (LP: #1166671) Remaining changes: + - debian/control, debian/patches/fix_smtp_banner.patch: + + Show Ubuntu distribution in SMTP banner. + + Build-Depends on lsb-release. + + -- Artur Rona Mon, 06 Jul 2015 12:09:36 +0200 + exim4 (4.86~RC4-2) unstable; urgency=medium * Drop libmysqlclient15-dev alternative build-dependency. Closes: #790463 @@ -1286,6 +1537,18 @@ -- Andreas Metzler Tue, 18 Nov 2014 19:28:20 +0100 +exim4 (4.84-8ubuntu1) vivid; urgency=low + + * Merge from Debian unstable. (LP: #1434300) Remaining changes: + - debian/control, debian/patches/fix_smtp_banner.patch: + + Show Ubuntu distribution in SMTP banner. + + Build-Depends on lsb-release. + - debian/control: + + Don't provide default-mta; in Ubuntu, + we want postfix to be the default. + + -- Artur Rona Thu, 19 Mar 2015 00:15:40 +0100 + exim4 (4.84-8) unstable; urgency=medium * Pull 83_Remove-limit-on-remove_headers-item-size.-Bug-1533.patch and @@ -1303,6 +1566,15 @@ -- Andreas Metzler Sat, 07 Feb 2015 15:12:33 +0100 +exim4 (4.84-6ubuntu1) vivid; urgency=medium + + * Resynchronise with Debian. Remaining changes: + - Show Ubuntu distribution in SMTP banner. + - Don't provide default-mta; in Ubuntu, we want postfix to be the + default. + + -- Colin Watson Wed, 14 Jan 2015 11:26:29 +0000 + exim4 (4.84-6) unstable; urgency=medium * Revert init script's restart order change in 4.84-4 for the time being. @@ -1311,6 +1583,15 @@ -- Andreas Metzler Sun, 21 Dec 2014 14:07:12 +0100 +exim4 (4.84-5ubuntu1) vivid; urgency=medium + + * Resynchronise with Debian. Remaining changes: + - Show Ubuntu distribution in SMTP banner. + - Don't provide default-mta; in Ubuntu, we want postfix to be the + default. + + -- Colin Watson Thu, 18 Dec 2014 15:26:17 +0000 + exim4 (4.84-5) unstable; urgency=medium * 82_quoted-or-r-2047-encoded.diff pulled from upstream git (sans @@ -1318,6 +1599,15 @@ -- Andreas Metzler Wed, 17 Dec 2014 19:03:39 +0100 +exim4 (4.84-4ubuntu1) vivid; urgency=medium + + * Resynchronise with Debian. Remaining changes: + - Show Ubuntu distribution in SMTP banner. + - Don't provide default-mta; in Ubuntu, we want postfix to be the + default. + + -- Colin Watson Tue, 02 Dec 2014 15:28:46 +0000 + exim4 (4.84-4) unstable; urgency=medium * Unset message_prefix/message_sufix in maildrop_pipe transport. Maildrop @@ -1332,6 +1622,15 @@ -- Andreas Metzler Sun, 30 Nov 2014 08:24:04 +0100 +exim4 (4.84-3ubuntu1) vivid; urgency=medium + + * Resynchronise with Debian. Remaining changes: + - Show Ubuntu distribution in SMTP banner. + - Don't provide default-mta; in Ubuntu, we want postfix to be the + default. + + -- Colin Watson Tue, 11 Nov 2014 13:43:35 +0000 + exim4 (4.84-3) unstable; urgency=medium * Apply patch to Italian (it) debconf template translation, thanks to @@ -1361,6 +1660,24 @@ -- Andreas Metzler Sat, 09 Aug 2014 07:42:00 +0200 +exim4 (4.84~RC1-3ubuntu2) utopic; urgency=medium + + * Rebuild for Perl 5.20.0. + + -- Colin Watson Thu, 21 Aug 2014 12:18:13 +0100 + +exim4 (4.84~RC1-3ubuntu1) utopic; urgency=low + + * Merge from Debian unstable (LP: #1351470). Remaining changes: + - Show Ubuntu distribution on smtp: + + debian/patches/fix_smtp_banner.patch: updated SMTP banner + with Ubuntu distribution + + debian/control: added lsb-release build dependency + - Don't provide default-mta; in Ubuntu, we want postfix to be the + default. + + -- Corey Bryant Mon, 04 Aug 2014 11:48:39 -0400 + exim4 (4.84~RC1-3) unstable; urgency=medium * Third try. Simply comment *custom* in debian/control. @@ -1429,6 +1746,18 @@ -- Andreas Metzler Thu, 29 May 2014 13:09:04 +0200 +exim4 (4.82.1-2ubuntu1) utopic; urgency=low + + * Merge from Debian unstable (LP: #1348074). Remaining changes: + - Show Ubuntu distribution on smtp: + + debian/patches/fix_smtp_banner.patch: updated SMTP banner + with Ubuntu distribution + + debian/control: added lsb-release build dependency + - Don't provide default-mta; in Ubuntu, we want postfix to be the + default. + + -- Robie Basak Fri, 25 Jul 2014 15:53:09 +0000 + exim4 (4.82.1-2) unstable; urgency=high * [87_double_expansion.diff] from upstream. Stop unwanted double expansion @@ -1446,6 +1775,18 @@ -- Andreas Metzler Wed, 28 May 2014 19:01:43 +0200 +exim4 (4.82-8ubuntu1) utopic; urgency=medium + + * Merge from Debian unstable. Remaining changes: + - Show Ubuntu distribution on smtp: + + debian/patches/fix_smtp_banner.patch: updated SMTP banner + with Ubuntu distribution + + debian/control: added lsb-release build dependency + - Don't provide default-mta; in Ubuntu, we want postfix to be the + default. + + -- Dimitri John Ledkov Sat, 17 May 2014 01:50:20 +0100 + exim4 (4.82-8) unstable; urgency=medium * Now that GMP has been relicensed to LGPLv3+/GPLv2+ build exim against @@ -1509,6 +1850,78 @@ -- Andreas Metzler Sun, 09 Feb 2014 19:41:34 +0100 +exim4 (4.82-3ubuntu2.4) trusty-security; urgency=medium + + * SECURITY UPDATE: Buffer overflow in base64d() + - debian/patches/CVE-2018-6789.patch: fix overflow in + src/auths/b64decode.c. + - CVE-2018-6789 + + -- Marc Deslauriers Sat, 10 Feb 2018 14:19:43 -0500 + +exim4 (4.82-3ubuntu2.3) trusty-security; urgency=medium + + * SECURITY UPDATE: memory leak + - debian/patches/CVE-2017-1000368.patch: free -p argument if + allocation was required. + - CVE-2017-1000368 + + -- Steve Beattie Fri, 02 Jun 2017 22:44:35 -0700 + +exim4 (4.82-3ubuntu2.2) trusty-security; urgency=medium + + * SECURITY UPDATE: DKIM information leakage + - debian/patches/CVE-2016-9963.patch: fix information leakage in + src/dkim.c, src/transports/smtp.c. + - CVE-2016-9963 + + -- Marc Deslauriers Thu, 05 Jan 2017 08:31:06 -0500 + +exim4 (4.82-3ubuntu2.1) trusty-security; urgency=medium + + * SECURITY UPDATE: privilege escalation via crafted lookup value + - debian/patches/CVE-2014-2972.patch: only expand integers for integer + math once. + - CVE-2014-2972 + * SECURITY UPDATE: privilege escalation when used with perl_startup + - debian/patches/CVE-2016-1531.patch: add new add_environment and + keep_environment configuration options. + - debian/patches/CVE-2016-1531-2.patch: don't issue env warning if env + is empty. + - debian/patches/CVE-2016-1531-3.patch: store the initial working + directory, expand $initial_cwd. + - debian/patches/CVE-2016-1531-4.patch: delay chdir(/) until we opened + the main config. + - Add macros MAIN_KEEP_ENVIRONMENT and MAIN_ADD_ENVIRONMENT to set the + new options. Set "keep_environment =" by default to avoid a runtime + warning. + - Bump exim4-config Breaks to exim4-daemon-* (<< 4.82-3ubuntu2.1). + - debian/exim4-config.NEWS: Add entry to warn of potential breakage. + - CVE-2016-1531 + * WARNING: This update may break existing installations. + + -- Marc Deslauriers Mon, 14 Mar 2016 12:57:00 -0400 + +exim4 (4.82-3ubuntu2) trusty; urgency=medium + + * debian/tests/control: Add missing python test dependency, as + debian/tests/security calls python. + + -- Martin Pitt Tue, 25 Feb 2014 17:33:13 +0100 + +exim4 (4.82-3ubuntu1) trusty; urgency=low + + * Merge from Debian unstable (LP: #1259620). Remaining changes: + - Show Ubuntu distribution on smtp: + + debian/patches/fix_smtp_banner.patch: updated SMTP banner + with Ubuntu distribution + + debian/control: added lsb-release build dependency + - Don't provide default-mta; in Ubuntu, we want postfix to be the + default. + - Build-depend on db5.3. + + -- Yolanda Robla Tue, 10 Dec 2013 17:07:20 +0000 + exim4 (4.82-3) unstable; urgency=low * Upload to unstable. @@ -1589,6 +2002,21 @@ -- Andreas Metzler Sun, 29 Sep 2013 14:43:25 +0200 +exim4 (4.80-9ubuntu2) trusty; urgency=low + + * Build-depend on libdb5.3-dev, instead of libdb5.1-dev. + + -- Dmitrijs Ledkovs Mon, 04 Nov 2013 12:14:54 +0000 + +exim4 (4.80-9ubuntu1) trusty; urgency=low + + * Resynchronise with Debian. Remaining changes: + - Don't provide default-mta; in Ubuntu, we want postfix to be the + default. + - Add "Ubuntu" to SMTP banner. + + -- Colin Watson Mon, 28 Oct 2013 11:55:21 -0700 + exim4 (4.80-9) unstable; urgency=low * Upload to unstable. @@ -1635,6 +2063,34 @@ -- Andreas Metzler Sun, 01 Sep 2013 15:58:49 +0200 +exim4 (4.80-7ubuntu4) trusty; urgency=low + + * Rebuild for Perl 5.18. + + -- Colin Watson Wed, 23 Oct 2013 10:24:08 +0100 + +exim4 (4.80-7ubuntu3) saucy; urgency=low + + * debian/patches/fix_smtp_banner.patch: updated SMTP banner + with Ubuntu distribution + * debian/control: added lsb-release build dependency + + -- Yolanda Robla Tue, 18 Jun 2013 19:17:43 +0200 + +exim4 (4.80-7ubuntu2) saucy; urgency=low + + * debian/tests: Add autopkgtest. + + -- Yolanda Mon, 27 May 2013 11:31:35 +0200 + +exim4 (4.80-7ubuntu1) raring; urgency=low + + * Merge from Debian unstable (LP: #1166383). Remaining changes: + - debian/control: Don't declare a Provides: default-mta; in Ubuntu, + we want postfix to be the default. + + -- Robie Basak Mon, 08 Apr 2013 18:13:15 +0100 + exim4 (4.80-7) unstable; urgency=low * Use exim's ${quote:xxx} operator when invoking spfquery to disallow @@ -1654,6 +2110,14 @@ -- Andreas Metzler Wed, 21 Nov 2012 19:08:53 +0100 +exim4 (4.80-5.1ubuntu1) raring; urgency=low + + * Merge from Debian. Remaining changes: + - debian/control: Don't declare a Provides: default-mta; in Ubuntu, + we want postfix to be the default. + + -- Oussama Bounaim Sun, 11 Nov 2012 07:11:06 +0100 + exim4 (4.80-5.1) unstable; urgency=high * Non-maintainer upload by the Security Team. @@ -1681,6 +2145,23 @@ -- Andreas Metzler Sat, 23 Jun 2012 18:35:03 +0200 +exim4 (4.80-3ubuntu1.1) quantal-security; urgency=low + + * SECURITY UPDATE: arbitrary code execution via dns decode logic + - debian/patches/CVE-2012-5671.patch: adjust max length and validate + against it in src/pdkim/pdkim.h, src/dkim.c. + - CVE-2012-5671 + + -- Marc Deslauriers Thu, 25 Oct 2012 08:22:46 -0400 + +exim4 (4.80-3ubuntu1) quantal; urgency=low + + * Merge from Debian unstable. Remaining changes: + - debian/control: Don't declare a Provides: default-mta; in Ubuntu, + we want postfix to be the default. + + -- Clint Byrum Thu, 14 Jun 2012 15:28:08 -0700 + exim4 (4.80-3) unstable; urgency=low * Pull 75_openssl_sni.diff from upstream. - Segfault caused by NULL @@ -1828,6 +2309,26 @@ -- Andreas Metzler Sat, 24 Sep 2011 18:36:08 +0200 +exim4 (4.76-3ubuntu3) precise; urgency=low + + * Rebuild for libmysqlclient transition + + -- Clint Byrum Wed, 23 Nov 2011 23:29:35 -0800 + +exim4 (4.76-3ubuntu2) precise; urgency=low + + * Rebuild for Perl 5.14. + + -- Colin Watson Wed, 16 Nov 2011 01:22:39 +0000 + +exim4 (4.76-3ubuntu1) precise; urgency=low + + * Merge from debian unstable. Remaining changes: + - debian/control: Don't declare a Provides: default-mta; in Ubuntu, + we want postfix to be the default. + + -- Stéphane Graber Thu, 20 Oct 2011 11:29:07 -0400 + exim4 (4.76-3) unstable; urgency=low * [exim4-base.cron.daily] Correct invocation of mail(1), options need to be @@ -1848,6 +2349,14 @@ -- Andreas Metzler Sun, 18 Sep 2011 11:49:13 +0200 +exim4 (4.76-2ubuntu1) oneiric; urgency=low + + * Merge from debian unstable. Remaining changes: + - debian/control: Don't declare a Provides: default-mta; in Ubuntu, + we want postfix to be the default. + + -- Stéphane Graber Mon, 30 May 2011 17:48:56 -0400 + exim4 (4.76-2) unstable; urgency=low * debian/rules: Remove test/ and test-stamp on clean. @@ -1860,6 +2369,14 @@ -- Andreas Metzler Sun, 29 May 2011 18:21:03 +0200 +exim4 (4.76-1ubuntu1) oneiric; urgency=low + + * Merge from debian unstable. Remaining changes (LP: #779391): + - debian/control: Don't declare a Provides: default-mta; in Ubuntu, + we want postfix to be the default. + + -- Stéphane Graber Mon, 23 May 2011 12:37:30 -0400 + exim4 (4.76-1) unstable; urgency=low * New upstream version. @@ -1906,6 +2423,14 @@ -- Andreas Metzler Fri, 06 May 2011 20:08:51 +0200 +exim4 (4.75-2ubuntu1) oneiric; urgency=low + + * Merge from debian unstable. Remaining changes: + - debian/control: Don't declare a Provides: default-mta; in Ubuntu, + we want postfix to be the default. + + -- Stéphane Graber Fri, 06 May 2011 14:51:28 -0400 + exim4 (4.75-2) unstable; urgency=low * clamav socket on Debian is clamd:/var/run/clamav/clamd.ctl, fix @@ -1948,6 +2473,24 @@ -- Andreas Metzler Thu, 24 Feb 2011 19:02:07 +0100 +exim4 (4.74-1ubuntu1) natty; urgency=low + + * Merge from debian experimental. Remaining changes: (LP: #713855) + - debian/patches/71_exiq_grep_error_on_messages_without_size.patch: + + Improve handling of broken messages when "exim4 -bp" (mailq) + reports lines without size info. (Closes: #528625) + - debian/control: Don't declare a Provides: default-mta; in Ubuntu, + we want postfix to be the default. + - debian/{control,rules}: Add and enable hardened build for PIE. + (Closes: #542726) + * Update 71_exiq_grep_error_on_messages_without_size.patch to get way + which upstream has fixed it. Probably it can be dropped with next + upstream release. + * This upload fixes CVE: (LP: #708023) + - CVE-2011-0017 + + -- Artur Rona Wed, 09 Feb 2011 21:31:35 +0100 + exim4 (4.74-1) experimental; urgency=low * 4.74 release, should build on hurd again. @@ -1973,6 +2516,20 @@ -- Andreas Metzler Sun, 23 Jan 2011 14:02:36 +0100 +exim4 (4.73~rc1-1ubuntu1) natty; urgency=low + + * Merge from debian unstable. Remaining changes: (LP: #697934) + - debian/patches/71_exiq_grep_error_on_messages_without_size.patch: + + Improve handling of broken messages when "exim4 -bp" (mailq) + reports lines without size info. + - debian/control: Don't declare a Provides: default-mta; in Ubuntu, + we want postfix to be the default. + - debian/{control,rules}: Add and enable hardened build for PIE. + (Closes: #542726) + * Drop B-D on libmysqlclient15-dev, resolved in Debian. + + -- Artur Rona Tue, 28 Dec 2010 22:20:17 +0100 + exim4 (4.73~rc1-1) experimental; urgency=low * New upstream release candidate. @@ -2068,6 +2625,20 @@ -- Andreas Metzler Sun, 26 Dec 2010 15:13:08 +0100 +exim4 (4.72-2ubuntu1) natty; urgency=low + + * Merge from debian unstable. Remaining changes: (LP: #671615) + - debian/patches/71_exiq_grep_error_on_messages_without_size.dpatch: + Improve handling of broken messages when "exim4 -bp" (mailq) reports + lines without size info. + - Don't declare a Provides: default-mta; in Ubuntu, we want postfix to be + the default. + - debian/control: Change build dependencies to MySQL 5.1. + - debian/{control,rules}: add and enable hardened build for PIE + (Closes: #542726). + + -- Artur Rona Fri, 05 Nov 2010 21:05:47 +0100 + exim4 (4.72-2) unstable; urgency=low [ Marc Haber ] @@ -2091,6 +2662,20 @@ -- Andreas Metzler Sat, 30 Oct 2010 13:38:26 +0200 +exim4 (4.72-1ubuntu1) maverick; urgency=low + + * Merge with Debian unstable (LP: #609620). Remaining changes: + + debian/patches/71_exiq_grep_error_on_messages_without_size.dpatch: + Improve handling of broken messages when "exim4 -bp" (mailq) reports + lines without size info. + + Don't declare a Provides: default-mta; in Ubuntu, we want postfix to be + the default. + + debian/control: Change build dependencies to MySQL 5.1. + + debian/{control,rules}: add and enable hardened build for PIE + (Closes: #542726). + + -- Artur Rona Sun, 25 Jul 2010 02:00:42 +0200 + exim4 (4.72-1) unstable; urgency=low * New upstream release. (Identical to the git snapshot previously @@ -2142,6 +2727,20 @@ -- Andreas Metzler Thu, 25 Mar 2010 17:34:30 +0100 +exim4 (4.71-3ubuntu1) lucid; urgency=low + + * Merge with Debian unstable (lp: #501657). Remaining changes: + + debian/patches/71_exiq_grep_error_on_messages_without_size.dpatch: + Improve handling of broken messages when "exim4 -bp" (mailq) reports + lines without size info. + + Don't declare a Provides: default-mta; in Ubuntu, we want postfix to be + the default. + + debian/control: Change build dependencies to MySQL 5.1. + + debian/{control,rules}: add and enable hardened build for PIE + (Debian bug 542726). + + -- Michael Bienia Fri, 01 Jan 2010 16:28:19 +0100 + exim4 (4.71-3) unstable; urgency=low * exim4-base.cron.daily: Do not run exim_tidydb on Berkeley DB logfiles. @@ -2256,6 +2855,35 @@ -- Andreas Metzler Sat, 17 Oct 2009 14:26:54 +0200 +exim4 (4.69-11ubuntu4) karmic; urgency=low + + * debian/{control,rules}: add and enable hardened build for PIE + (Debian bug 542726). + + -- Kees Cook Thu, 20 Aug 2009 17:33:26 -0700 + +exim4 (4.69-11ubuntu3) karmic; urgency=low + + * debian/control: Change build dependencies to MySQL 5.1. + + -- Mathias Gug Mon, 17 Aug 2009 17:57:26 -0400 + +exim4 (4.69-11ubuntu2) karmic; urgency=low + + * Don't declare a Provides: default-mta; in Ubuntu, we want postfix to be + the default. + + -- Steve Langasek Wed, 03 Jun 2009 15:39:14 +0000 + +exim4 (4.69-11ubuntu1) karmic; urgency=low + + * Merge from debian unstable (LP: #375923), remaining changes: + - debian/patches/71_exiq_grep_error_on_messages_without_size.dpatch: + Improve handling of broken messages when "exim4 -bp" (mailq) reports + lines without size info + + -- Thierry Carrez Wed, 13 May 2009 12:15:29 +0200 + exim4 (4.69-11) unstable; urgency=medium * Build-Depend on lynx-cur|lynx instead of lynx. (lynx is just a dummy @@ -2313,6 +2941,15 @@ -- Andreas Metzler Sat, 02 May 2009 09:05:56 +0200 +exim4 (4.69-9ubuntu1) jaunty; urgency=low + + [ Daniel van Eeden ] + * debian/patches/71_exiq_grep_error_on_messages_without_size.dpatch: + Improve handling of broken messages when "exim4 -bp" (mailq) reports lines + w/o size info, LP: #18194 + + -- Dustin Kirkland Wed, 11 Feb 2009 06:43:52 -0600 + exim4 (4.69-9) unstable; urgency=medium * [update-exim4.conf]: Use POSIX character classes [:alnum:] or explicit diff -Nru exim4-4.92/debian/control exim4-4.92/debian/control --- exim4-4.92/debian/control 2019-02-17 12:13:18.000000000 +0000 +++ exim4-4.92/debian/control 2019-03-05 11:39:23.000000000 +0000 @@ -1,7 +1,8 @@ Source: exim4 Section: mail Priority: standard -Maintainer: Exim4 Maintainers +Maintainer: Ubuntu Developers +XSBC-Original-Maintainer: Exim4 Maintainers Uploaders: Andreas Metzler , Marc Haber @@ -31,7 +32,8 @@ libxt-dev, lynx, po-debconf, - xsltproc + xsltproc, + lsb-release Package: exim4-base Architecture: any diff -Nru exim4-4.92/debian/patches/fix_smtp_banner.patch exim4-4.92/debian/patches/fix_smtp_banner.patch --- exim4-4.92/debian/patches/fix_smtp_banner.patch 1970-01-01 00:00:00.000000000 +0000 +++ exim4-4.92/debian/patches/fix_smtp_banner.patch 2019-03-05 11:24:10.000000000 +0000 @@ -0,0 +1,53 @@ +Description: Add EXIM_DISTRIBUTION var to display it on the SMTP banner +Origin: https://blueprints.launchpad.net/ubuntu/+spec/servercloud-s-server-app-banner-updates +Author: Yolanda Robla +Forwarded: https://salsa.debian.org/exim-team/exim4/merge_requests/2 +Last-Update: 2018-07-03 + +--- a/src/globals.c ++++ b/src/globals.c +@@ -1443,7 +1443,7 @@ int smtp_accept_queue_per_connection = 10; + int smtp_accept_reserve = 0; + uschar *smtp_active_hostname = NULL; + uschar *smtp_banner = US"$smtp_active_hostname ESMTP " +- "Exim $version_number $tod_full" ++ "Exim $version_number " EXIM_DISTRIBUTION " $tod_full" + "\0<---------------Space to patch smtp_banner->"; + int smtp_ch_index = 0; + uschar *smtp_cmd_argument = NULL; +--- a/src/config.h.defaults ++++ b/src/config.h.defaults +@@ -224,4 +224,6 @@ for EXIM_ARITH_MAX and _MIN in OS/oh.h-FOO */ + #define SC_EXIM_ARITH "%" SCNi64 /* scanf incl. 0x prefix */ + #define SC_EXIM_DEC "%" SCNd64 /* scanf decimal */ + ++#define EXIM_DISTRIBUTION ++ + /* End of config.h.defaults */ +--- a/scripts/Configure-config.h ++++ b/scripts/Configure-config.h +@@ -23,6 +23,12 @@ + if [ "$1" != "" ] ; then MAKE=$1 ; fi + if [ "$MAKE" = "" ] ; then MAKE=make ; fi + ++# exporting distribution to use it in smtp banner ++if test -x /usr/bin/lsb_release && lsb_release -si; then ++ export EXIM_DISTRIBUTION=\"$(lsb_release -si)\" ++else ++ export EXIM_DISTRIBUTION=\"\" ++fi + $MAKE buildconfig || exit 1 + + # BEWARE: tab characters needed in the following sed command. They have had +--- a/src/exim.h ++++ b/src/exim.h +@@ -597,5 +597,9 @@ default to EDQUOT if it exists, otherwise ENOSPC. */ + # define EXIM_GROUPLIST_SIZE NGROUPS_MAX + #endif + ++#ifndef EXIM_DISTRIBUTION ++ #define EXIM_DISTRIBUTION "" ++#endif ++ + #endif + /* End of exim.h */ diff -Nru exim4-4.92/debian/patches/series exim4-4.92/debian/patches/series --- exim4-4.92/debian/patches/series 2019-03-22 06:14:04.000000000 +0000 +++ exim4-4.92/debian/patches/series 2019-03-25 11:02:33.000000000 +0000 @@ -17,3 +17,4 @@ 75_09-OpenSSL-Fix-aggregation-of-messages.patch 75_10-Harden-plaintext-authenticator.patch 90_localscan_dlopen.dpatch +fix_smtp_banner.patch