-
amavisd-new (1:2.13.0-3ubuntu1.1) mantic-security; urgency=medium
* SECURITY UPDATE: incorrect check via multiple boundary parameters
- debian/patches/CVE-2024-28054-1.patch: add CC_UNCHECKED,3 content
category in conf/amavisd.conf, lib/Amavis.pm, lib/Amavis/Conf.pm,
lib/Amavis/Unpackers.pm, lib/Amavis/Unpackers/MIME.pm,
lib/Amavis/Unpackers/Part.pm, t/Amavis/Unpackers/MIMETest.pm.
- debian/patches/CVE-2024-28054-2.patch: use
MIME::Entity->ambiguous_content if available in .gitlab-ci.yml,
lib/Amavis/Unpackers/MIME.pm.
- debian/patches/CVE-2024-28054-3.patch: describe CVE-2024-28054 in
README_FILES/README.CVE-2024-28054.
- CVE-2024-28054
-- Marc Deslauriers <email address hidden> Fri, 12 Apr 2024 11:03:05 -0400
-
amavisd-new (1:2.13.0-3ubuntu1) mantic; urgency=medium
* Merge with Debian unstable (LP: #2018057). Remaining changes:
- d/README.Debian: Add information about the Ubuntu variant of
amavisd-new and the major differences between that package in
Ubuntu and Debian to raise awareness about the additional config
file which is 40-policy_banks.
- d/README.Debian, d/etc/conf.d/21-ubuntu_defaults: Enable DKIM
verification and reducing verbosity about sending mail.
+ Reduce email responses for virus/blocked mail so as not to be a
backscatter source by default.
+ Enable DKIM checking by default.
- d/README.Debian, d/etc/conf.d/40-policy_banks: Include policy-bank
of known good domains for DKIM whitelisting in 40-policy_banks.
- d/control: Drop altermime and ripole to Suggests as they are
optional and universe dependencies (LP: 992879).
- d/control, d/amavisd-new-postfix.*: New package amavisd-new-postfix,
configuration for anti-spam/virus.
- do not report FQDN misconfiguration through apport.
(LP #1587695).
+ d/control: b-dep on dh_apparmor.
+ d/rules: enable dh_apparmor.
+ d/amavisd-new.apport: apport script
+ d/amavisd-new.dirs: layout required dirs
* New Changes:
- d/control: Delete packages ripole and dspam - which are missing -
from Suggests to not mislead anyone who would want to make use of
those (LP: #1891643).
- d/rules: fix build with (empty) amavisd-new-postfix
-- Michal Maloszewski <email address hidden> Mon, 17 Jul 2023 23:17:01 +0200
-
amavisd-new (1:2.12.2-1.1ubuntu1) lunar; urgency=medium
* Merge from Debian unstable (LP: #1993383). Remaining changes:
- Add information in README.Debian about Ubuntu specific changes.
- d/README.Debian, d/etc/conf.d/21-ubuntu_defaults: Ubuntu
configuration changes in 21-ubuntu_defaults.
+ Reduce email responses for virus/blocked mail so as not to be
a backscatter source by default.
+ Enable DKIM checking by default.
- d/README.Debian,d/etc/conf.d/40-policy_banks: Include
policy-bank of known good domains for DKIM whitelisting
in 40-policy_banks.
- d/control: drop altermime and ripole to Suggests after
discussions with the server team.
- d/control,d/amavisd-new-postfix.*: new package
amavisd-new-postfix, configuration for anti-spam/virus.
- do not report FQDN misconfiguration through apport.
(LP #1587695).
+ d/control: b-dep on dh_apparmor
+ d/rules: enable dh_apparmor
+ d/amavisd-new.apport: apport script
+ d/amavisd-new.dirs: layout required dirs
-- Sergio Durigan Junior <email address hidden> Fri, 18 Nov 2022 14:23:22 -0500