303 Commits

Author SHA256 Message Date
Ana Guerrero
519d221e78 Accepting request 1243176 from server:mail
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1243176
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=83
2025-02-04 17:14:52 +00:00
722ac25aff fix broken changes file format
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=294
2025-01-28 15:55:20 +00:00
Ana Guerrero
882d8e0197 Accepting request 1225066 from server:mail
OBS-URL: https://build.opensuse.org/request/show/1225066
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=82
2024-11-19 21:23:25 +00:00
45bd5a1cfe - Own /srv/www which is no longer owned by the filesystem package.
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=292
2024-11-19 11:47:30 +00:00
Ana Guerrero
4051e53e82 Accepting request 1187596 from server:mail
- update to 4.98 (bsc#1227423, CVE-2024-39929):
  * The dkim_status ACL condition may now be used in data ACLs
  * The dkim_verbose logging control also enables logging of signing
  * The dkim_timestamps signing option now accepts zero to include
    a current timestamp but no expiry timestamp.
  * The recipients_max main option is now expanded.
  * Setting variables for "exim -be" can set a tainted value.
  * A dns:fail event.
  * The dsearch lookup supports search for a sub-path.
  * Include mailtest utility for simple connection checking.
  * Add SMTP WELLKNOWN extension.

OBS-URL: https://build.opensuse.org/request/show/1187596
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=81
2024-07-16 20:02:33 +00:00
18cf88956e - update to 4.98 (bsc#1227423, CVE-2024-39929):
* The dkim_status ACL condition may now be used in data ACLs
  * The dkim_verbose logging control also enables logging of signing
  * The dkim_timestamps signing option now accepts zero to include
    a current timestamp but no expiry timestamp.
  * The recipients_max main option is now expanded.
  * Setting variables for "exim -be" can set a tainted value.
  * A dns:fail event.
  * The dsearch lookup supports search for a sub-path.
  * Include mailtest utility for simple connection checking.
  * Add SMTP WELLKNOWN extension.

OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=290
2024-07-15 16:28:08 +00:00
Ana Guerrero
df2f96bab3 Accepting request 1149269 from server:mail
OBS-URL: https://build.opensuse.org/request/show/1149269
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=80
2024-02-22 20:00:23 +00:00
Peter Wullinger
23ca122ac2 Accepting request 1149241 from home:dimstar:rpm4.20:e
Prepare for RPM 4.20

OBS-URL: https://build.opensuse.org/request/show/1149241
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=288
2024-02-22 11:41:27 +00:00
Dominique Leuenberger
91ae279aa6 Accepting request 1135763 from server:mail
- update to 4.97.1 (bsc#1218387, CVE-2023-51766):
  * Fixes for the smtp protocol smuggling (CVE-2023-51766)

    passed over a connection could use BDAT; any further ones using DATA.
    proxy.
- Update eximstats-html-update.py to run under Python 3.
 * CVE-2019-13917: Fixed an issue with ${sort} expansion which could
   allow remote attackers to execute other programs with root privileges
- Replace xorg-x11-devel by individual pkgconfig() buildrequires.
- Replace references to /var/adm/fillup-templates with new
    + fix CVE-2016-1531
      argument.

OBS-URL: https://build.opensuse.org/request/show/1135763
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=79
2024-01-03 11:25:47 +00:00
f7b71cc6f2 OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=286 2023-12-30 16:14:29 +00:00
5e68cef9d9 - update to 4.97.1 (bsc#1218387, CVE-2023-51766):
* Fixes for the smtp protocol smuggling (CVE-2023-51766)

    passed over a connection could use BDAT; any further ones using DATA.
    proxy.
- Update eximstats-html-update.py to run under Python 3.
 * CVE-2019-13917: Fixed an issue with ${sort} expansion which could
   allow remote attackers to execute other programs with root privileges
- Replace xorg-x11-devel by individual pkgconfig() buildrequires.
- Replace references to /var/adm/fillup-templates with new
    + fix CVE-2016-1531
      argument.

OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=285
2023-12-30 15:37:11 +00:00
Ana Guerrero
10af80844a Accepting request 1123800 from server:mail
- update to exim 4.97
  * remove patch-no-exit-on-rewrite-malformed-address.patch (upstreamed)

OBS-URL: https://build.opensuse.org/request/show/1123800
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=78
2023-11-07 20:26:56 +00:00
Peter Wullinger
dd0e2195ac Accepting request 1123799 from home:pwcau:branches:server:mail
- update to exim 4.97
  * remove patch-no-exit-on-rewrite-malformed-address.patch (upstreamed)

OBS-URL: https://build.opensuse.org/request/show/1123799
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=283
2023-11-07 09:38:26 +00:00
Peter Wullinger
5851a46be1 Accepting request 1123795 from home:pwcau:branches:server:mail
- update to exim 4.97

OBS-URL: https://build.opensuse.org/request/show/1123795
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=282
2023-11-07 09:33:41 +00:00
Ana Guerrero
8ad96661f8 Accepting request 1117952 from server:mail
- security update to exim 4.96.2
  * fixes CVE-2023-42117 (bsc#1215787)
  * fixes CVE-2023-42119 (bsc#1215789)

OBS-URL: https://build.opensuse.org/request/show/1117952
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=77
2023-10-16 20:33:24 +00:00
Peter Wullinger
343bf8e3f1 Accepting request 1117949 from home:pwcau:branches:server:mail
typo in version

OBS-URL: https://build.opensuse.org/request/show/1117949
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=280
2023-10-16 09:08:04 +00:00
Peter Wullinger
69f682e4be Accepting request 1117947 from home:pwcau:branches:server:mail
- security update to exim 4.96.2
  * fixes CVE-2023-42117 (bsc#1215787)
  * fixes CVE-2023-42119 (bsc#1215789)

OBS-URL: https://build.opensuse.org/request/show/1117947
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=279
2023-10-16 09:05:28 +00:00
Ana Guerrero
e4e0b4acd2 Accepting request 1114826 from server:mail
- security update to exim 4.96.1
  * fixes CVE-2023-42114 (bsc#1215784)
  * fixes CVE-2023-42115 (bsc#1215785)
  * fixes CVE-2023-42116 (bsc#1215786)

OBS-URL: https://build.opensuse.org/request/show/1114826
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=76
2023-10-02 18:05:12 +00:00
Peter Wullinger
ed51ffdd94 add proper source files
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=277
2023-10-02 13:30:56 +00:00
Peter Wullinger
1b126813a8 Accepting request 1114822 from home:pwcau:branches:server:mail
- security update to exim 4.96.1
  * fixes CVE-2023-42114 (bsc#1215784)
  * fixes CVE-2023-42115 (bsc#1215785)
  * fixes CVE-2023-42116 (bsc#1215786)

OBS-URL: https://build.opensuse.org/request/show/1114822
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=276
2023-10-02 13:23:30 +00:00
Peter Wullinger
d358e67d5d Accepting request 1114687 from home:pwcau:branches:server:mail
- add patch (patch-CVE-2023-42115-CVE-2023-42116-CVE-2023-42114.patch) for
  * CVE-2023-42114 (bsc#1215784)
  * CVE-2023-42115 (bsc#1215785)
  * CVE-2023-42116 (bsc#1215786)

OBS-URL: https://build.opensuse.org/request/show/1114687
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=275
2023-10-02 06:44:29 +00:00
Peter Wullinger
d4072b44a4 Accepting request 1114683 from home:pwcau:branches:server:mail
- add patch for
  * CVE-2023-42114 (bsc#1215784)
  * CVE-2023-42115 (bsc#1215785)
  * CVE-2023-42116 (bsc#1215786)

OBS-URL: https://build.opensuse.org/request/show/1114683
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=274
2023-10-02 06:36:36 +00:00
Dominique Leuenberger
016ffaa458 Accepting request 1077219 from server:mail
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1077219
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=75
2023-04-04 19:27:25 +00:00
Peter Wullinger
6568568245 Accepting request 1075052 from home:pwcau:branches:server:mail
enable sender rewriting support (SUPPORT_SRS)

SUPPORT_SRS has no extra dependencies and seems stable, so we can enable it by default.

OBS-URL: https://build.opensuse.org/request/show/1075052
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=272
2023-03-28 17:08:20 +00:00
Dominique Leuenberger
9910bea95c Accepting request 1062004 from server:mail
OBS-URL: https://build.opensuse.org/request/show/1062004
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=74
2023-01-30 16:11:17 +00:00
Peter Wullinger
59feea161a Accepting request 1060890 from home:kukuk:branches:server:mail
- Don't build the NIS module anymore, libnsl/NIS are deprecated

OBS-URL: https://build.opensuse.org/request/show/1060890
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=270
2023-01-30 08:27:01 +00:00
Dominique Leuenberger
7f0553aef3 Accepting request 1029728 from server:mail
- add patch-cve-2022-3559 (fixes CVE-2022-3559, bsc#1204427, Bug 2915)

OBS-URL: https://build.opensuse.org/request/show/1029728
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=73
2022-10-19 11:17:29 +00:00
Peter Wullinger
488a048fdd Accepting request 1029726 from home:pwcau:branches:server:mail
- add patch-cve-2022-3559 (fixes CVE-2022-3559, bsc#1204427, Bug 2915)

OBS-URL: https://build.opensuse.org/request/show/1029726
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=268
2022-10-18 11:52:11 +00:00
Richard Brown
1edc09e78b Accepting request 1006967 from server:mail
- add (patch-no-exit-on-rewrite-malformed-address.patch)
  Fix exit on attempt to rewrite a malformed address (Bug 2903)
- Own /var/spool/mail (boo#1179574)
- Migration to /usr/etc: Saving user changed configuration files
  in /etc and restoring them while an RPM update.

OBS-URL: https://build.opensuse.org/request/show/1006967
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=72
2022-09-29 16:14:43 +00:00
Peter Wullinger
b6ac902ba3 actually apply patch
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=266
2022-09-29 14:05:12 +00:00
Peter Wullinger
c9e5a39bde Accepting request 1006962 from home:pwcau:branches:server:mail
- add (patch-no-exit-on-rewrite-malformed-address.patch)
  Fix exit on attempt to rewrite a malformed address (Bug 2903)

OBS-URL: https://build.opensuse.org/request/show/1006962
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=265
2022-09-29 14:00:47 +00:00
Peter Wullinger
390576486d Accepting request 1000599 from home:schubi2
- Migration to /usr/etc: Saving user changed configuration files
  in /etc and restoring them while an RPM update.

OBS-URL: https://build.opensuse.org/request/show/1000599
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=264
2022-09-07 06:59:43 +00:00
Peter Wullinger
bb32cd54e8 Accepting request 1001404 from home:lnussel:branches:server:mail
- Own /var/spool/mail (boo#1179574)

OBS-URL: https://build.opensuse.org/request/show/1001404
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=263
2022-09-07 06:58:15 +00:00
Dominique Leuenberger
43e9264029 Accepting request 985854 from server:mail
OBS-URL: https://build.opensuse.org/request/show/985854
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=71
2022-06-30 11:18:21 +00:00
Peter Wullinger
bdb9594915 Accepting request 985853 from home:schubi2
- Moved logrotate files from user specific directory /etc/logrotate.d
  to vendor specific directory /usr/etc/logrotate.d.

OBS-URL: https://build.opensuse.org/request/show/985853
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=261
2022-06-29 14:37:00 +00:00
Peter Wullinger
f60227c059 Accepting request 985275 from home:pwcau:branches:server:mail
- update to exim 4.96
  * Move from using the pcre library to pcre2.
  * Constification work in the filters module required a major version
    bump for the local-scan API.  Specifically, the "headers_charset"
    global which is visible via the API is now const and may therefore
    not be modified by local-scan code.
  * Bug 2819: speed up command-line messages being read in.  Previously a
    time check was being done for every character; replace that with one
    per buffer.
  * Bug 2815: Fix ALPN sent by server under OpenSSL.  Previously the string
    sent was prefixed with a length byte.
  * Change the SMTP feature name for pipelining connect to be compliant with
    RFC 5321.  Previously Dovecot (at least) would log errors during
    submission.
  * Fix macro-definition during "-be" expansion testing.  The move to
    write-protected store for macros had not accounted for these runtime
    additions; fix by removing this protection for "-be" mode.
  * Convert all uses of select() to poll().
  * Fix use of $sender_host_name in daemon process.  When used in certain
    main-section options or in a connect ACL, the value from the first ever
    connection was never replaced for subsequent connections.
  * Bug 2838: Fix for i32lp64 hard-align platforms
  * Bug 2845: Fix handling of tls_require_ciphers for OpenSSL when a value
    with underbars is given.
  * Bug 1895: TLS: Deprecate RFC 5114 Diffie-Hellman parameters.
  * Debugging initiated by an ACL control now continues through into routing
    and transport processes.
  * The "expand" debug selector now gives more detail, specifically on the
    result of expansion operators and items.
  * Bug 2751: Fix include_directory in redirect routers.  Previously a
    bad comparison between the option value and the name of the file to
    be included was done, and a mismatch was wrongly identified.
  * Support for Berkeley DB versions 1 and 2 is withdrawn.
  * When built with NDBM for hints DB's check for nonexistence of a name
    supplied as the db file-pair basename.
  * Remove the "allow_insecure_tainted_data" main config option and the
    "taint" log_selector.
  * Fix static address-list lookups to properly return the matched item.
    Previously only the domain part was returned.
  * The ${run} expansion item now expands its command string elements after
    splitting.  Previously it was before; the new ordering makes handling
    zero-length arguments simpler.
  * Taint-check exec arguments for transport-initiated external processes.
    Previously, tainted values could be used.  This affects "pipe", "lmtp" and
    "queryprogram" transport, transport-filter, and ETRN commands.
    The ${run} expansion is also affected: in "preexpand" mode no part of
    the command line may be tainted, in default mode the executable name
    may not be tainted.
  * Fix CHUNKING on a continued-transport.  Previously the usabilility of
    the facility was not passed across execs, and only the first message
    passed over a connection could use BDAT; any further ones using DATA. 
  * Support the PIPECONNECT facility in the smtp transport when the helo_data
    uses $sending_ip_address and an interface is specified.
  * OpenSSL: fix transport-required OCSP stapling verification under session
    resumption.
  * TLS resumption: the key for session lookup in the client now includes
    more info that a server could potentially use in configuring a TLS
    session, avoiding oferring mismatching sessions to such a server.
  * Fix string_copyn() for limit greater than actual string length.
  * Bug 2886: GnuTLS: Do not free the cached creds on transport connection
    close; it may be needed for a subsequent connection.
  * Fix CHUNKING for a second message on a connection when the first was
    rejected.
  * Fix ${srs_encode ...} to handle an empty sender address, now returning
    an empty address.
  * Bug 2855: Handle a v4mapped sender address given us by a frontending
    proxy.

OBS-URL: https://build.opensuse.org/request/show/985275
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=260
2022-06-27 09:57:54 +00:00
Dominique Leuenberger
ff4bbdda85 Accepting request 947395 from server:mail
- disable ProtectHome=, it prevents local delivery (bsc#1194810)

OBS-URL: https://build.opensuse.org/request/show/947395
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=70
2022-01-19 23:12:24 +00:00
Peter Wullinger
fcee07e240 - disable ProtectHome=, it prevents local delivery (bsc#1194810)
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=259
2022-01-19 11:42:39 +00:00
Peter Wullinger
5f57c8cb27 - disable ProtectHome=, it prevents local delivery
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=258
2022-01-19 11:42:03 +00:00
Dominique Leuenberger
1a13667d51 Accepting request 922122 from server:mail
OBS-URL: https://build.opensuse.org/request/show/922122
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=69
2021-10-05 20:33:38 +00:00
Peter Wullinger
3a0f978ef1 Accepting request 922121 from home:pwcau:branches:server:mail
mention taintwarn patch removal

OBS-URL: https://build.opensuse.org/request/show/922121
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=257
2021-09-29 07:43:25 +00:00
Peter Wullinger
6fcdc365d7 Accepting request 922115 from home:pwcau:branches:server:mail
- update to exim 4.95
  * fast-ramp queue run
  * native SRS
  * TLS resumption
  * LMDB lookups with single key
  * smtp transport option "message_linelength_limit"
  * optionally ignore lookup caches
  * quota checking for appendfile transport during message reception
  * sqlite lookups allow a "file=<path>" option
  * lsearch lookups allow a "ret=full" option
  * command line option for the notifier socket
  * faster TLS startup
  * new main config option "proxy_protocol_timeout"
  * expand "smtp_accept_max_per_connection"
  * log selector "queue_size_exclusive"
  * main config option "smtp_backlog_monitor"
  * main config option "hosts_require_helo"
  * main config option "allow_insecure_tainted_data"

OBS-URL: https://build.opensuse.org/request/show/922115
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=256
2021-09-29 07:33:08 +00:00
Dominique Leuenberger
fbb3642a79 Accepting request 918956 from server:mail
OBS-URL: https://build.opensuse.org/request/show/918956
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=68
2021-09-14 19:14:52 +00:00
Peter Wullinger
c36f5e1f4e Accepting request 918945 from home:jsegitz:branches:systemdhardening:server:mail
Automatic systemd hardening effort by the security team. This has not been tested. For details please see https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort

OBS-URL: https://build.opensuse.org/request/show/918945
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=255
2021-09-14 14:18:57 +00:00
Dominique Leuenberger
4404793c68 Accepting request 906449 from server:mail
OBS-URL: https://build.opensuse.org/request/show/906449
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=67
2021-07-15 22:00:43 +00:00
e9ae9fc6c1 Accepting request 904696 from home:StevenK:branches:server:mail
- Update eximstats-html-update.py to run under Python 3.

OBS-URL: https://build.opensuse.org/request/show/904696
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=254
2021-07-15 10:29:19 +00:00
Dominique Leuenberger
381900c4b7 Accepting request 893769 from server:mail
OBS-URL: https://build.opensuse.org/request/show/893769
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=66
2021-05-17 16:45:36 +00:00
Peter Wullinger
9a6c8fe8e0 Accepting request 893758 from home:pwcau:branches:server:mail
- add exim-4.94.2+fixes and taintwarn patches (taintwarn.patch)

OBS-URL: https://build.opensuse.org/request/show/893758
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=252
2021-05-17 14:40:18 +00:00
Dominique Leuenberger
c2dc05e40b Accepting request 890644 from server:mail
OBS-URL: https://build.opensuse.org/request/show/890644
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/exim?expand=0&rev=65
2021-05-05 18:40:00 +00:00
Peter Wullinger
5d0e28acb2 Accepting request 890643 from home:AndreasStieger:branches:server:mail
some changelog OCD

OBS-URL: https://build.opensuse.org/request/show/890643
OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=250
2021-05-05 09:48:27 +00:00