Re: [exim] STARTTLS issue: Exim not affected

Top Page
Delete this message
Reply to this message
Author: Todd Lyons
Date:  
To: Exim Users
CC: Phil Pennock
Subject: Re: [exim] STARTTLS issue: Exim not affected
On Wed, Mar 16, 2011 at 10:42 PM, Phil Pennock <pdp@???> wrote:
>
> During the RC process for Exim 4.75, we were notified of a possible
> issue in Exim, as part of a general "much software has this problem"
> alert, by CERT.  The issue relates to STARTTLS and command injection,
> as described by Wietse Venema at:
>  http://article.gmane.org/gmane.mail.postfix.user/218905


Is this the main factor in what has held up the release process for
4.75? It's been at RC3 for a couple weeks now, was just curious if it
will move to release status now that this has been thoroughly
investigated.

--
Regards...      Todd
"It is the nature of the human species to reject what is true but
unpleasant and to embrace what is obviously false but comforting." &
"The chief source of problems is solutions."