Re: [exim] Security release for CVE-2016-1531: 4.84.2, 4.85.…

Top Page
Delete this message
Reply to this message
Author: Heiko Schlittermann
Date:  
To: Heiko Schlichting
CC: exim-users
Subject: Re: [exim] Security release for CVE-2016-1531: 4.84.2, 4.85.2, 4.86.2, 4.87 RC5
Heiko Schlichting <exim-users@???> (Di 08 Mär 2016 10:29:51 CET):
> Heiko Schlittermann wrote:
> >
> >     keep_environment = TZ : LANG : ^LC_ : ^LDAP
> >     add_environment = <; PATH=/bin:/usr/bin:/usr/local/bin

> >
> > could be a good starting point.
>
> The handling of "TZ" is very special and often does noch work as expected.
> Your list suggests that TZ content will be used from the environment but
> this is often not the case. It depends on
>
>     * if and how TZ is set at compile time
>     * TIMEZONE_DEFAULT setting in Makefile at compile time
>     * "timezone" global config variable


Phew, that's confusing indeed. I'll put there some notice into the spec
file about TZ. That the TZ environment is subject the above things plus
timestamps_utc.

> Here are two examples which I found confusing until reading the source in
> src/buildconfig.c:
>
>     $ exim -bP add_environment
>     add_environment = TZ=Atlantic/Reykjavik


>     $ env TZ=Atlantic/Reykjavik exim -bP environment
>     TZ=Europe/Berlin


Thanks for forcing clarification.

    Best regards from Dresden/Germany
    Viele Grüße aus Dresden
    Heiko Schlittermann
-- 
 SCHLITTERMANN.de ---------------------------- internet & unix support -
 Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
 gnupg encrypted messages are welcome --------------- key ID: F69376CE -
 ! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -