LWN.net Logo

Fedora alert FEDORA-2013-15049 (ssmtp)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 19 Update: ssmtp-2.64-9.fc19
Date:  Fri, 30 Aug 2013 22:59:08 +0000
Message-ID:  <20130830225908.C9EBB217C1@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-15049 2013-08-20 22:21:05 -------------------------------------------------------------------------------- Name : ssmtp Product : Fedora 19 Version : 2.64 Release : 9.fc19 URL : http://packages.debian.org/stable/mail/ssmtp Summary : Extremely simple MTA to get mail off the system to a Mailhub Description : A secure, effective and simple way of getting mail off a system to your mail hub. It contains no suid-binaries or other dangerous things - no mail spool to poke around in, and no daemons running in the background. Mail is simply forwarded to the configured mailhost. Extremely easy configuration. WARNING: the above is all it does; it does not receive mail, expand aliases or manage a queue. That belongs on a mail hub with a system administrator. -------------------------------------------------------------------------------- Update Information: Use a corrected patch to validate server certificates Removes world read access from the configuration file thus prohibiting reading of password stored inside it. Removes world read access from the configuration file thus prohibiting reading of password stored inside it. -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 20 2013 Manuel "lonely wolf" Wolfshant <wolfy@fedoraproject.org> - 2.64-9 - replace TLS patch with a corrected one. thanks Till Maas for the fix * Sun Aug 4 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.64-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Wed Jun 5 2013 Manuel "lonely wolf" Wolfshant <wolfy@fedoraproject.org> - 2.64-7 - remove world readable permissions of the config file (#962988) - revive the authpass patch (#970123) - revive improved default config settings which were lost during rebase (#895708) -------------------------------------------------------------------------------- References: [ 1 ] Bug #864894 - ssmtp: Does not validate server certificates when using TLS connection https://bugzilla.redhat.com/show_bug.cgi?id=864894 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ssmtp' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds