Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 …

Top Page
Delete this message
Reply to this message
Author: Victor Ustugov
Date:  
To: Victor Ustugov via Exim-users
Subject: Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)
Victor Ustugov via Exim-users wrote on 05.05.2021 17:14:
> Heiko Schlittermann via Exim-users wrote on 05.05.2021 16:16:


>>>>>> I'd just refuse to create a bloated 4.94+fixes, instead of releasing
>>>>>> 4.95 as soon as possible.
>>>>>
>>>>> Yesterday I built exim 4.94.2 with adapted code from Jeremy's commit.
>>>>> It works as expected on FreeBSD (exim 4.94.2 from ports with my patches)
>>>>> and Ubuntu (exim 4.94.2-1 built from Debian deb-src with my patches).
>>>>
>>>> What did you do?
>>>
>>> I built exim 4.94.2 with patch
>>> https://mta.org.ua/exim-4.94-conf/patches/exim-4.94%2Bfixes-fix-sqlite-tainted-filename/patch-src__exim-4.94%2Bfixes-fix-sqlite-tainted-filename.patch
>>>
>>> As I remember patch for exim 4.94 based on:
>>>
>>> https://git.exim.org/exim.git/patch/44644c2e404a3ea0191db0b0458e86924fb240bb
>> This one isn't related to the file= feture
>
> As far as I remember I could not build exim 4.94 with
> 4a7dca52352d0976f200b89a50825433b7551554 and
> b8514d1960e259d49ab2c84c89eba52ab993da3f without
> 44644c2e404a3ea0191db0b0458e86924fb240bb
>
>
>> These both I located too and "backported" to 4.94.2 (as did too,
>> probably):
>>> https://git.exim.org/exim.git/patch/4a7dca52352d0976f200b89a50825433b7551554
>>> https://git.exim.org/exim.git/patch/b8514d1960e259d49ab2c84c89eba52ab993da3f
>>
>> See the attached patches.
>
> Thanks. I'll try to build exim with these patches today evening.


Heiko, I took a look to your patches.
Except for the files related to documentation and tests, our patches are
identical. So no need to rebuild exim and check patches again.

Thank you again.


>> @Odhiambo: as it seems you're building your own version of Exim, we
>> recommend you the patches from Victor or my (attached). Currently we do
>> not plan to do the backport officially, because we'll start working
>> to release 4.95 as soon as possible.
>
>



-- 
Best wishes
Victor Ustugov        mailto:victor@corvax.kiev.ua
Skype ID: corvax_nb   JID: victor@???
public GnuPG/PGP key: https://victor.corvax.kiev.ua/corvax.asc