-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 06 Mar 2024 10:10:14 -0500 Source: postfix Binary: postfix postfix-cdb postfix-cdb-dbgsym postfix-dbgsym postfix-ldap postfix-ldap-dbgsym postfix-lmdb postfix-lmdb-dbgsym postfix-mysql postfix-mysql-dbgsym postfix-pcre postfix-pcre-dbgsym postfix-pgsql postfix-pgsql-dbgsym postfix-sqlite postfix-sqlite-dbgsym Architecture: arm64 Version: 3.7.11-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-03) Changed-By: Scott Kitterman Description: postfix - High-performance mail transport agent postfix-cdb - CDB map support for Postfix postfix-ldap - LDAP map support for Postfix postfix-lmdb - LMDB map support for Postfix postfix-mysql - MySQL map support for Postfix postfix-pcre - PCRE map support for Postfix postfix-pgsql - PostgreSQL map support for Postfix postfix-sqlite - SQLite map support for Postfix Changes: postfix (3.7.11-0+deb12u1) bookworm; urgency=medium . [Wietse Venema] . * 3.7.11 - Bugfix (defect introduced: Postfix 2.3, date 20051222): the Dovecot auth client did not reset the 'reason' from a previous Dovecot auth service response, before parsing the next Dovecot auth server response in the same SMTP session. Reported by Stephan Bosch, File: xsasl/xsasl_dovecot_server.c. - Cleanup: Postfix SMTP server response with an empty authentication failure reason. File: smtpd/smtpd_sasl_glue.c. - Bugfix (defect introduced: Postfix 3.1, date: 20151128): "postqueue -j" produced broken JSON when escaping a control character as \uXXXX. Found during code maintenance. File: postqueue/showq_json.c. - Cleanup: posttls-finger certificate match expectations for all TLS security levels, including warnings for levels that don't implement certificate matching. Viktor Dukhovni. File: posttls-finger.c. - Bugfix (defect introduced: Postfix 2.3): after prepending a message header with a Postfix access table PREPEND action, a Milter request to delete or update an existing header could have no effect, or it could target the wrong instance of an existing header. Root cause: the fix dated 20141018 for the Postfix Milter client was incomplete. The client did correctly hide the first, Postfix-generated, Received: header when sending message header information to a Milter with the smfi_header() application callback function, but it was still hiding the first header (instead of the first Received: header) when handling requests from a Milter to delete or update an existing header. Problem report by Carlos Velasco. This change was verified to have no effect on requests from a Milter to add or insert a header. File: cleanup/cleanup_milter.c. - Workaround: tlsmgr logfile spam. Some OS lies under load: it says that a socket is readable, then it says that the socket has unread data, and then it says that read returns EOF, causing Postfix to spam the log with a warning message. File: tlsmgr/tlsmgr.c. - Bugfix (defect introduced: Postfix 3.4): the SMTP server's BDAT command handler could be tricked to read $message_size_limit bytes into memory. Found during code maintenance. File: smtpd/smtpd.c. - Performance: eliminate worst-case behavior where the queue manager defers delivery to all destinations over a specific delivery transport, after only a single delivery agent failure. The scheduler now throttles one destination, and allows deliveries to other destinations to keep making progress. Files: *qmgr/qmgr_deliver.c. - Safety: drop and log over-size DNS responses resulting in more than 100 records. This 20x larger than the number of server addresses that the Postfix SMTP client is willing to consider when delivering mail, and is well below the number of records that could cause a tail recursion crash in dns_rr_append() as reported by Toshifumi Sakaguchi. This also limits the number of DNS requests from check_*_*_access restrictions. Files: dns/dns.h, dns/dns_lookup.c, dns/dns_rr.c, dns/test_dns_lookup.c, posttls-finger/posttls-finger.c, smtp/smtp_addr.c, smtpd/smtpd_check.c. Checksums-Sha1: 2dc46c85019468ad56a0bcdcbae07d87b36e34fb 10440 postfix-cdb-dbgsym_3.7.11-0+deb12u1_arm64.deb fd8be5f884f83abf6c87f1f2314f2b6c022ffb6f 333616 postfix-cdb_3.7.11-0+deb12u1_arm64.deb 9fd2e1a789ee0b253be86d28f96d7eaf88f8bd09 1824272 postfix-dbgsym_3.7.11-0+deb12u1_arm64.deb 5ba0801cae8c829193a272dae55aa35c97694d40 22468 postfix-ldap-dbgsym_3.7.11-0+deb12u1_arm64.deb af94ec37366bdd632d62dbf8d244d1421b3f260a 350300 postfix-ldap_3.7.11-0+deb12u1_arm64.deb b35f0381dce5b090b6e70b719fd9d6fb0440bf6a 18604 postfix-lmdb-dbgsym_3.7.11-0+deb12u1_arm64.deb a9540d391360382bd0bfa8b810dc97dff52c7824 339004 postfix-lmdb_3.7.11-0+deb12u1_arm64.deb 150e0fcaeb10698041132763e9c580cfdea1fd2d 23332 postfix-mysql-dbgsym_3.7.11-0+deb12u1_arm64.deb 20a9772448322b54409e7028b0ba832c1bb54931 341224 postfix-mysql_3.7.11-0+deb12u1_arm64.deb b0feeac46b269dd41b010859b905d288e59f483f 14940 postfix-pcre-dbgsym_3.7.11-0+deb12u1_arm64.deb 30828144ad08aff8336588e60ae7f6947c375853 339672 postfix-pcre_3.7.11-0+deb12u1_arm64.deb 4188b6402c8b67bc4f3938cf2feaadffe48f1cf2 13800 postfix-pgsql-dbgsym_3.7.11-0+deb12u1_arm64.deb 9dad0dc773678084dcd37837ea2de97c3f7f29ac 339984 postfix-pgsql_3.7.11-0+deb12u1_arm64.deb da37672c767870fffaab6c1f60cc1bd6d93b1ff8 8352 postfix-sqlite-dbgsym_3.7.11-0+deb12u1_arm64.deb e5d0d82261e45b67a1f7d58e1a0fba67df4277ba 337312 postfix-sqlite_3.7.11-0+deb12u1_arm64.deb 09cbcbc00b41acac57ee40351e2a4cbe112a714e 11740 postfix_3.7.11-0+deb12u1_arm64-buildd.buildinfo 4c3c7144b4771d8965fe6da00e85c75c1751707a 1455040 postfix_3.7.11-0+deb12u1_arm64.deb Checksums-Sha256: c59f29ae65ea69e352edd325f2377e75ef69c5ead247b442e0f591774959ac60 10440 postfix-cdb-dbgsym_3.7.11-0+deb12u1_arm64.deb c39eefb283b6040b2f5dcdcaebd6a8dde96f42accf069936f0d90f912718e5d9 333616 postfix-cdb_3.7.11-0+deb12u1_arm64.deb 9038b99954e407fb14a76246ed2118f3d8abd08cd7e37e91d75ba5e6828f7315 1824272 postfix-dbgsym_3.7.11-0+deb12u1_arm64.deb 9707cbe7850584d48c420b298bbd611e53078bba2795cba566ed109cef0d35eb 22468 postfix-ldap-dbgsym_3.7.11-0+deb12u1_arm64.deb ce208049a6856047556182dfc3f16f6f831495a1cfcb0fb9b3b299c5f675bf35 350300 postfix-ldap_3.7.11-0+deb12u1_arm64.deb 8935cb0c4ab5cffb1a448f9fcad1aa477c8c7060e96eabddd4c78a529be09c63 18604 postfix-lmdb-dbgsym_3.7.11-0+deb12u1_arm64.deb 853407b88dda6fd3827081ac1aabe8fe0e54ce5fb23601b9db10a76222cd3276 339004 postfix-lmdb_3.7.11-0+deb12u1_arm64.deb 7b5e5c718b3bdba3fcb1ecf9584ab56d37dc26d71cf91003902f67e7e5648beb 23332 postfix-mysql-dbgsym_3.7.11-0+deb12u1_arm64.deb 11087337953adc45f5e5a42b33e5e763f752dd858a96c8cb68844aa04f6386e6 341224 postfix-mysql_3.7.11-0+deb12u1_arm64.deb 8e238d4ddb06e9c05e4588148afbbf0509ff0a3982ca4e9f38d01299db247199 14940 postfix-pcre-dbgsym_3.7.11-0+deb12u1_arm64.deb 1cb7279909a2e8f1f22727a42f0d4f636c115af57b6669214f1aaa6a26d6f606 339672 postfix-pcre_3.7.11-0+deb12u1_arm64.deb fb1550cd94da6472ffded1549dc6b73d64348c3f18cb7db2a503d541ce6a5f75 13800 postfix-pgsql-dbgsym_3.7.11-0+deb12u1_arm64.deb 4425f4862f4578cb732f9ef324ca8754e37607002ee603e8be09ffe995caa1a6 339984 postfix-pgsql_3.7.11-0+deb12u1_arm64.deb e8b79d6b37ab2db4e9e9700a60ce1c277598f6b0294ead91754c445a2854a726 8352 postfix-sqlite-dbgsym_3.7.11-0+deb12u1_arm64.deb 8ef70ac65850fd36407970e847e713690a0d2b05a23003779682fada398c8312 337312 postfix-sqlite_3.7.11-0+deb12u1_arm64.deb c94bbeb0c0a6de8a743f8a269c78bb80d901e4dd06b287de78552c6b63efb769 11740 postfix_3.7.11-0+deb12u1_arm64-buildd.buildinfo a936d9ced5be9aaf877388f0453618cd7ea83302a26313e65bdb22d8d339fed6 1455040 postfix_3.7.11-0+deb12u1_arm64.deb Files: 1cbadd918891f2d7cf7548aae3de275b 10440 debug optional postfix-cdb-dbgsym_3.7.11-0+deb12u1_arm64.deb ae641932e40016406a11ecc1f4764283 333616 mail optional postfix-cdb_3.7.11-0+deb12u1_arm64.deb f8dff880e7638d8d42dba35551fb388d 1824272 debug optional postfix-dbgsym_3.7.11-0+deb12u1_arm64.deb 77a750e38ac1e80bfb0b0d0639407111 22468 debug optional postfix-ldap-dbgsym_3.7.11-0+deb12u1_arm64.deb bc80984366bb49af135a78b36f630397 350300 mail optional postfix-ldap_3.7.11-0+deb12u1_arm64.deb 552d780c620475aa5277b17513522383 18604 debug optional postfix-lmdb-dbgsym_3.7.11-0+deb12u1_arm64.deb 178832e8f3f6ef04f11ee7eac6b14129 339004 mail optional postfix-lmdb_3.7.11-0+deb12u1_arm64.deb 274d23d566cf1100a00eb9ae860ec0e0 23332 debug optional postfix-mysql-dbgsym_3.7.11-0+deb12u1_arm64.deb 2df1c94094dbdc1e8e246553158cd2df 341224 mail optional postfix-mysql_3.7.11-0+deb12u1_arm64.deb 1cd9dc93f3d827054d3befbca5737583 14940 debug optional postfix-pcre-dbgsym_3.7.11-0+deb12u1_arm64.deb 08f6086431ed0ea8e162db239bccec6a 339672 mail optional postfix-pcre_3.7.11-0+deb12u1_arm64.deb a993ff4667f695001e37404c60bc815d 13800 debug optional postfix-pgsql-dbgsym_3.7.11-0+deb12u1_arm64.deb 0b387d9ed066ef3fa01047f0d6fab3a9 339984 mail optional postfix-pgsql_3.7.11-0+deb12u1_arm64.deb 0b1a0bd4754db3a577c0fd616879f7c1 8352 debug optional postfix-sqlite-dbgsym_3.7.11-0+deb12u1_arm64.deb 8c26423aa4c48613979f8cd22b163c09 337312 mail optional postfix-sqlite_3.7.11-0+deb12u1_arm64.deb df65d1df7636c2872bae71f91a810230 11740 mail optional postfix_3.7.11-0+deb12u1_arm64-buildd.buildinfo 2d8a134c0aee948fc69edcbb17294f4a 1455040 mail optional postfix_3.7.11-0+deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEV2QMHg/7F9BmqsxiZLztDiV8cXAFAmYAo5EACgkQZLztDiV8 cXC6MxAAqK+4A2Gla/nP6BIzV/PgA9mbKP9B061TZGgj5wMBT+zVxy/8KDQ3UA9M sm5Ri8evDqOI83AGH+raKTHBAEooUKYJOUduDQ/Kj/BPtCObbIHWiw6WmxUaTiOC lQFZv/TlHxErrUIn7mV9xn0U7temMMzF4YEB49kKCemReBsXDYNO1sBhfQ9CDpe/ YFm1FBwb9PDMwZw7LiRRdcR7u7SzOl9NRAvxOXGRCaXCRuzNdA/dO2GtTxqsy70g fjq2dDATZXBmDTIGsErbHZK0UMDZ5893uFkKM9GOOMWnB7IG50Oufwfd2nsV1Cop y49PaVOoCE3uIgpYweyqEjz2hz9oshYIH87YxjMG1n7pnpONUwFsqmcxKzahJ6iE 12khQGx+qwPezS7hNjMWnDnbDrQcB3gpjixXWBaqHhwjdity0lIozhfwNZNwdNVq oLcBb/9/ExdsqD0X7y30ZSyadW/aaTEZ8s49LjfODqGJFQknEtB0JumfpZB61zlu 1R0pDDf4wdZoraxuBxgJXiZVVqjls5afGzV/Tx1jsjLuEuP7DV1bVwOWgkZUf1Kr bZXMM63axhgL0XXmfrn3Z+sI+4jCin3MeRCtu+XxPBinNV1QViuP2HGGE84LwhcM G3+nQWUIDVvSjQ48QeAKBygHvrbjbFJs85wZeZlFAUa+DzucycY= =RWKV -----END PGP SIGNATURE-----