-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 09 Mar 2024 10:38:51 -0500 Source: postfix Binary: postfix postfix-cdb postfix-cdb-dbgsym postfix-dbgsym postfix-ldap postfix-ldap-dbgsym postfix-lmdb postfix-lmdb-dbgsym postfix-mysql postfix-mysql-dbgsym postfix-pcre postfix-pcre-dbgsym postfix-pgsql postfix-pgsql-dbgsym postfix-sqlite postfix-sqlite-dbgsym Architecture: mipsel Version: 3.5.25-0+deb11u1 Distribution: bullseye Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Scott Kitterman Description: postfix - High-performance mail transport agent postfix-cdb - CDB map support for Postfix postfix-ldap - LDAP map support for Postfix postfix-lmdb - LMDB map support for Postfix postfix-mysql - MySQL map support for Postfix postfix-pcre - PCRE map support for Postfix postfix-pgsql - PostgreSQL map support for Postfix postfix-sqlite - SQLite map support for Postfix Changes: postfix (3.5.25-0+deb11u1) bullseye; urgency=medium . [Wietse Venema] . * 3.5.25 - Bugfix (defect introduced: Postfix 2.3, date 20051222): the Dovecot auth client did not reset the 'reason' from a previous Dovecot auth service response, before parsing the next Dovecot auth server response in the same SMTP session. Reported by Stephan Bosch, File: xsasl/xsasl_dovecot_server.c. - Cleanup: Postfix SMTP server response with an empty authentication failure reason. File: smtpd/smtpd_sasl_glue.c. - Bugfix (defect introduced: Postfix 3.1, date: 20151128): "postqueue -j" produced broken JSON when escaping a control character as \uXXXX. Found during code maintenance. File: postqueue/showq_json.c. - Cleanup: posttls-finger certificate match expectations for all TLS security levels, including warnings for levels that don't implement certificate matching. Viktor Dukhovni. File: posttls-finger.c. - Bugfix (defect introduced: Postfix 2.3): after prepending a message header with a Postfix access table PREPEND action, a Milter request to delete or update an existing header could have no effect, or it could target the wrong instance of an existing header. Root cause: the fix dated 20141018 for the Postfix Milter client was incomplete. The client did correctly hide the first, Postfix-generated, Received: header when sending message header information to a Milter with the smfi_header() application callback function, but it was still hiding the first header (instead of the first Received: header) when handling requests from a Milter to delete or update an existing header. Problem report by Carlos Velasco. This change was verified to have no effect on requests from a Milter to add or insert a header. File: cleanup/cleanup_milter.c. - Workaround: tlsmgr logfile spam. Some OS lies under load: it says that a socket is readable, then it says that the socket has unread data, and then it says that read returns EOF, causing Postfix to spam the log with a warning message. File: tlsmgr/tlsmgr.c. - Bugfix (defect introduced: Postfix 3.4): the SMTP server's BDAT command handler could be tricked to read $message_size_limit bytes into memory. Found during code maintenance. File: smtpd/smtpd.c. - Performance: eliminate worst-case behavior where the queue manager defers delivery to all destinations over a specific delivery transport, after only a single delivery agent failure. The scheduler now throttles one destination, and allows deliveries to other destinations to keep making progress. Files: *qmgr/qmgr_deliver.c. - Safety: drop and log over-size DNS responses resulting in more than 100 records. This 20x larger than the number of server addresses that the Postfix SMTP client is willing to consider when delivering mail, and is well below the number of records that could cause a tail recursion crash in dns_rr_append() as reported by Toshifumi Sakaguchi. This also limits the number of DNS requests from check_*_*_access restrictions. Files: dns/dns.h, dns/dns_lookup.c, dns/dns_rr.c, dns/test_dns_lookup.c, posttls-finger/posttls-finger.c, smtp/smtp_addr.c, smtpd/smtpd_check.c. Checksums-Sha1: 6bb6797f4d03fa5f012aafe01e5b1d0560559515 9852 postfix-cdb-dbgsym_3.5.25-0+deb11u1_mipsel.deb a8c65e124d1ea5b381fb40b7a3ebe9736456c7e7 364472 postfix-cdb_3.5.25-0+deb11u1_mipsel.deb 43c6b83942a883f16c031f95449aab11cef9d161 2007564 postfix-dbgsym_3.5.25-0+deb11u1_mipsel.deb defdf9bc440b385eb69525c0773a4cbd561e7173 20884 postfix-ldap-dbgsym_3.5.25-0+deb11u1_mipsel.deb 8d640eff131d5c73212f56b6208647a4ba3bf5a5 381624 postfix-ldap_3.5.25-0+deb11u1_mipsel.deb cd5699cba4ba0ac20def44b8fb672cc29fc8f83f 18044 postfix-lmdb-dbgsym_3.5.25-0+deb11u1_mipsel.deb 4c281e8a6003d2aebb3b0951b26b4aea198f4017 370144 postfix-lmdb_3.5.25-0+deb11u1_mipsel.deb be727d94894bef98f704c5950d24c4d4418549bf 23092 postfix-mysql-dbgsym_3.5.25-0+deb11u1_mipsel.deb e07c516f1d1c9753889c8c59fc4fa6bc001d6407 371916 postfix-mysql_3.5.25-0+deb11u1_mipsel.deb c96b02f979cfa9410156e2183b7996c6edda20f9 13948 postfix-pcre-dbgsym_3.5.25-0+deb11u1_mipsel.deb 4393ae51a7ab3212e9b056cf07453eaeaf952a2f 370052 postfix-pcre_3.5.25-0+deb11u1_mipsel.deb 6da950ae93a1c5b5788cdfa0de13499ebe058ddd 12864 postfix-pgsql-dbgsym_3.5.25-0+deb11u1_mipsel.deb 060aecb0a6ee0b1472ccff33bb9700b0de5edd5a 370744 postfix-pgsql_3.5.25-0+deb11u1_mipsel.deb fc16dfb55507bd3cb45561bb7e67d4280b5c18cc 7560 postfix-sqlite-dbgsym_3.5.25-0+deb11u1_mipsel.deb 432d045cad6248da14f64d536bb7a15ff947ff13 367856 postfix-sqlite_3.5.25-0+deb11u1_mipsel.deb 24591cf36cdc257828a6c2bf7457e561723e6f13 12063 postfix_3.5.25-0+deb11u1_mipsel-buildd.buildinfo 54d260883b8ee130e60c537eabbc8bca0a6cac25 1496020 postfix_3.5.25-0+deb11u1_mipsel.deb Checksums-Sha256: 6665ab202e5744cd100a4208f947c6c4c9c7c1d5c06c94a4680fe316ff80e1e7 9852 postfix-cdb-dbgsym_3.5.25-0+deb11u1_mipsel.deb 93a5c1302c00d5fc26599804fdff2c66762d6e8f7373ed7adc61979259c48fe6 364472 postfix-cdb_3.5.25-0+deb11u1_mipsel.deb 95747e3b3245bbdd38201262922e08073d5ab652dfb122751922cd715c20ec48 2007564 postfix-dbgsym_3.5.25-0+deb11u1_mipsel.deb 9127592f051447f141f88eaaa716798fa8b7e3d6640f6d9e8c724a37084fa2b8 20884 postfix-ldap-dbgsym_3.5.25-0+deb11u1_mipsel.deb 19d183b0bbed6f7c4d4332bea28ec2508e29aa7893e883db8ea07e330e9d8a4e 381624 postfix-ldap_3.5.25-0+deb11u1_mipsel.deb 99280526fc9a490d0b0a28c2cf86bdaea04d98bfff69473d9cb21a08b6553ac3 18044 postfix-lmdb-dbgsym_3.5.25-0+deb11u1_mipsel.deb 750fd11ff782057d569d5656988dd6dea3c8ad42951887ea716ec7a3cb2ff053 370144 postfix-lmdb_3.5.25-0+deb11u1_mipsel.deb 700022c83663c16d95bab4e249a866f3f6a8c7faa69c283a699d2ee788baabe4 23092 postfix-mysql-dbgsym_3.5.25-0+deb11u1_mipsel.deb 30b3eb3c142ddc71289bee04f29c1b66559a7d8b6671819a92da90f5905de090 371916 postfix-mysql_3.5.25-0+deb11u1_mipsel.deb 47fb55294aaf36981e6dbaedbb4de587c9f04528f4317d7511352d7dffcfb553 13948 postfix-pcre-dbgsym_3.5.25-0+deb11u1_mipsel.deb 5fe5e58ea963f5f8916c512fb464d381dee21f3a1b6d4f06e4a90bb20933fba2 370052 postfix-pcre_3.5.25-0+deb11u1_mipsel.deb 15c7e0b5a4e9e1ea07a422d0d3f4a9c58a0438fcd7d2082eab161e014ec7a314 12864 postfix-pgsql-dbgsym_3.5.25-0+deb11u1_mipsel.deb 961aaf81f853b2d7778ab792544ec3460fe1d5238972fed086bca5062d80d03f 370744 postfix-pgsql_3.5.25-0+deb11u1_mipsel.deb e654402471625639121c1336b5c7cca22446fbc2313894361928f25f9c3f84b5 7560 postfix-sqlite-dbgsym_3.5.25-0+deb11u1_mipsel.deb 07431c46583aba5345cd742535bf7e4e941137deb128210c80286749438482a8 367856 postfix-sqlite_3.5.25-0+deb11u1_mipsel.deb 313994e07629deb89f300d1b3a5f4a92a4a76615530b8eb22897b10dba889e91 12063 postfix_3.5.25-0+deb11u1_mipsel-buildd.buildinfo ddc495fe9bd070b2e8064fe8aa4cd455a724bf0307bf9eb0684244db2b9d5a1c 1496020 postfix_3.5.25-0+deb11u1_mipsel.deb Files: 0ab81ead5a51ecc4ba4bffec76a023e3 9852 debug optional postfix-cdb-dbgsym_3.5.25-0+deb11u1_mipsel.deb a38bf15c241d0a3ace950e64858348ac 364472 mail optional postfix-cdb_3.5.25-0+deb11u1_mipsel.deb 74b0d2031a531a2533f92bca682cd31a 2007564 debug optional postfix-dbgsym_3.5.25-0+deb11u1_mipsel.deb 7db6ceaa97bad354fb80fd00ad8c4be9 20884 debug optional postfix-ldap-dbgsym_3.5.25-0+deb11u1_mipsel.deb 58f67cec44c39b9eccaa71f68cb84a99 381624 mail optional postfix-ldap_3.5.25-0+deb11u1_mipsel.deb 59baabfeeac908273b6a72837f17dbf5 18044 debug optional postfix-lmdb-dbgsym_3.5.25-0+deb11u1_mipsel.deb 3c545309f5f87bec52cef19274bf034a 370144 mail optional postfix-lmdb_3.5.25-0+deb11u1_mipsel.deb 6421c15b05a8e1a9e2e669bb9f7a9481 23092 debug optional postfix-mysql-dbgsym_3.5.25-0+deb11u1_mipsel.deb 7a7383ff579059b569cadc43c03bb681 371916 mail optional postfix-mysql_3.5.25-0+deb11u1_mipsel.deb 6a8d45a25a42155d2ffb4a2358467309 13948 debug optional postfix-pcre-dbgsym_3.5.25-0+deb11u1_mipsel.deb 364a2d74a6d40566df597b88840e0e09 370052 mail optional postfix-pcre_3.5.25-0+deb11u1_mipsel.deb 7868bf3b7e40d3166305fa63e460a38f 12864 debug optional postfix-pgsql-dbgsym_3.5.25-0+deb11u1_mipsel.deb c8a52495bf307fca1eb35da44489cfae 370744 mail optional postfix-pgsql_3.5.25-0+deb11u1_mipsel.deb c5473380e346fb1899a77dac4e66dda8 7560 debug optional postfix-sqlite-dbgsym_3.5.25-0+deb11u1_mipsel.deb 6c69c71d8022c50eef60327654290104 367856 mail optional postfix-sqlite_3.5.25-0+deb11u1_mipsel.deb d9979fa16990dab585319588cba31d35 12063 mail optional postfix_3.5.25-0+deb11u1_mipsel-buildd.buildinfo 48b35feccbb9035034050c9668ffbd99 1496020 mail optional postfix_3.5.25-0+deb11u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEunmvxaaGKuI+hxxClmZGXOM83t8FAmYm0rcACgkQlmZGXOM8 3t+dDRAAjjiyjd+PnwzQgMru87Ud7JfuzA/psPXgSj5zvwS4WO4ytNjFDq/Ja/lp 9AihX1S9Hi+KBFjU44Xp0GEp3fQaAh41WM0wqMkovk8DH82nQ4U33UU60p1YIuHX M96bcgQcrMt+pyhS5sQGMUGdR5s2TKavFAKeJHwF1vT8MhvFS7DaO9EitL5HqfVA rVnhVShcdIurYlgpxElzt9vA+GV3/Tsx0Y87CliwilNpD+cR+aLQ0MND7gIFANSt 6Hr91U1eP/yuydV49+8PHHUuyDDkkUSjdK+TZNEw3bs4l+Re5qNjJ2+hWonH9wlf 5JkWGEXJyzg7RTeMXdgo4Pg49L2XV3yxGydEhmxy57QCshTHVQefA+hRLlDXGBQo GodaZVwLGbuI8cg3rs7DEUJUo9I7vOsrlBoTHujYhdnnjTGcO9xIuojxsEtetAH7 z8kFiciXMeKG3lzeftJJzCXxSvOrnzgwqQeLu8WWTb0EGSt2F7jPxLhQeRUFiZVK bSBSdnPlKdcpMFyZ8u3bWXgindFJMyttWq8STu3w+zOrvWCg+vD89o8sygHOkUFM m4jGY45DNBlulFvNtcbSjyHIBw1HHisVVgerSOeqPGLggI/7ywB2fdIqH/TugJxT OixTpNeltzknEwbC6UnXuvZgn05sMcWmqwViipgq8/WCN36dpug= =2FzT -----END PGP SIGNATURE-----