postfix 3.7.10-0+deb12u1 source package in Debian

Changelog

postfix (3.7.10-0+deb12u1) bookworm; urgency=medium

  [Wietse Venema]

  * 3.7.10
    - Security (outbound SMTP smuggling): with the default setting
      "cleanup_replace_stray_cr_lf = yes" Postfix will replace
      stray <CR> or <LF> characters in message content with a
      space character. This prevents Postfix from enabling
      outbound (remote) SMTP smuggling, and it also makes evaluation
      of Postfix-added DKIM etc. signatures independent from how
      a remote mail server handles stray <CR> or <LF> characters.
      Files: global/mail_params.h, cleanup/cleanup.c,
      cleanup/cleanup_message.c, mantools/postlink, proto/postconf.proto.
    - Security (inbound SMTP smuggling): with "smtpd_forbid_bare_newline
      = normalize" (default "no" for Postfix < 3.9), the Postfix
      SMTP server requires the standard End-of-DATA sequence
      <CR><LF>.<CR><LF>, and otherwise allows command or message
      content lines ending in the non-standard <LF>, processing
      them as if the client sent the standard <CR><LF>.
      The alternative setting, "smtpd_forbid_bare_newline = reject"
      will reject any command or message that contains a bare
      <LF>, and is more likely to cause problems with legitimate
      clients.
      For backwards compatibility, local clients are excluded by
      default with "smtpd_forbid_bare_newline_exclusions =
      $mynetworks".
      Files: mantools/postlink, proto/postconf.proto,
      global/mail_params.h, global/smtp_stream.c, global/smtp_stream.h,
      smtpd/smtpd.c, smtpd/smtpd_check.[hc].

 -- Scott Kitterman <email address hidden>  Fri, 26 Jan 2024 18:44:58 -0500

Upload details

Uploaded by:
LaMont Jones
Uploaded to:
Bookworm
Original maintainer:
LaMont Jones
Architectures:
any all
Section:
mail
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Bookworm release main mail

Builds

Downloads

File Size SHA-256 Checksum
postfix_3.7.10-0+deb12u1.dsc 2.9 KiB 4d3a1e599277d9ac9331ae12228cfc16176e5557cc5345d8e958d9c42a69220c
postfix_3.7.10.orig.tar.gz 4.6 MiB 7c0cba641dc0d8ce28cfc63f244b419e1cc6c8ce1fc55640820d85c7167b906c
postfix_3.7.10.orig.tar.gz.asc 220 bytes d05dc17fc622e979824063b8ad0d3c2b4fa394cdf8f13402446d11548febd1eb
postfix_3.7.10-0+deb12u1.debian.tar.xz 193.4 KiB c9a6f77f2711bc28675e8f461a6a9d4ee83183896651d8e819e4a04c19f26949

No changes file available.

Binary packages built by this source