-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 06 Mar 2024 10:10:14 -0500 Source: postfix Binary: postfix postfix-cdb postfix-cdb-dbgsym postfix-dbgsym postfix-ldap postfix-ldap-dbgsym postfix-lmdb postfix-lmdb-dbgsym postfix-mysql postfix-mysql-dbgsym postfix-pcre postfix-pcre-dbgsym postfix-pgsql postfix-pgsql-dbgsym postfix-sqlite postfix-sqlite-dbgsym Architecture: ppc64el Version: 3.7.11-0+deb12u1 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Scott Kitterman Description: postfix - High-performance mail transport agent postfix-cdb - CDB map support for Postfix postfix-ldap - LDAP map support for Postfix postfix-lmdb - LMDB map support for Postfix postfix-mysql - MySQL map support for Postfix postfix-pcre - PCRE map support for Postfix postfix-pgsql - PostgreSQL map support for Postfix postfix-sqlite - SQLite map support for Postfix Changes: postfix (3.7.11-0+deb12u1) bookworm; urgency=medium . [Wietse Venema] . * 3.7.11 - Bugfix (defect introduced: Postfix 2.3, date 20051222): the Dovecot auth client did not reset the 'reason' from a previous Dovecot auth service response, before parsing the next Dovecot auth server response in the same SMTP session. Reported by Stephan Bosch, File: xsasl/xsasl_dovecot_server.c. - Cleanup: Postfix SMTP server response with an empty authentication failure reason. File: smtpd/smtpd_sasl_glue.c. - Bugfix (defect introduced: Postfix 3.1, date: 20151128): "postqueue -j" produced broken JSON when escaping a control character as \uXXXX. Found during code maintenance. File: postqueue/showq_json.c. - Cleanup: posttls-finger certificate match expectations for all TLS security levels, including warnings for levels that don't implement certificate matching. Viktor Dukhovni. File: posttls-finger.c. - Bugfix (defect introduced: Postfix 2.3): after prepending a message header with a Postfix access table PREPEND action, a Milter request to delete or update an existing header could have no effect, or it could target the wrong instance of an existing header. Root cause: the fix dated 20141018 for the Postfix Milter client was incomplete. The client did correctly hide the first, Postfix-generated, Received: header when sending message header information to a Milter with the smfi_header() application callback function, but it was still hiding the first header (instead of the first Received: header) when handling requests from a Milter to delete or update an existing header. Problem report by Carlos Velasco. This change was verified to have no effect on requests from a Milter to add or insert a header. File: cleanup/cleanup_milter.c. - Workaround: tlsmgr logfile spam. Some OS lies under load: it says that a socket is readable, then it says that the socket has unread data, and then it says that read returns EOF, causing Postfix to spam the log with a warning message. File: tlsmgr/tlsmgr.c. - Bugfix (defect introduced: Postfix 3.4): the SMTP server's BDAT command handler could be tricked to read $message_size_limit bytes into memory. Found during code maintenance. File: smtpd/smtpd.c. - Performance: eliminate worst-case behavior where the queue manager defers delivery to all destinations over a specific delivery transport, after only a single delivery agent failure. The scheduler now throttles one destination, and allows deliveries to other destinations to keep making progress. Files: *qmgr/qmgr_deliver.c. - Safety: drop and log over-size DNS responses resulting in more than 100 records. This 20x larger than the number of server addresses that the Postfix SMTP client is willing to consider when delivering mail, and is well below the number of records that could cause a tail recursion crash in dns_rr_append() as reported by Toshifumi Sakaguchi. This also limits the number of DNS requests from check_*_*_access restrictions. Files: dns/dns.h, dns/dns_lookup.c, dns/dns_rr.c, dns/test_dns_lookup.c, posttls-finger/posttls-finger.c, smtp/smtp_addr.c, smtpd/smtpd_check.c. Checksums-Sha1: 3bef404af58f436fa0834f3f8b3e5b7667091708 10892 postfix-cdb-dbgsym_3.7.11-0+deb12u1_ppc64el.deb ca3e77e27dd6cb2f6d7d4693fc85349f901f189a 334152 postfix-cdb_3.7.11-0+deb12u1_ppc64el.deb 1616c27195a9eb738a09f290606a2969f697d948 1857032 postfix-dbgsym_3.7.11-0+deb12u1_ppc64el.deb ba4161d6efeabb6a9dbce2fd74d55e316acc5b68 23264 postfix-ldap-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 430fe04a4e5c7adc4e07dfc8a118a2a2dff93581 351504 postfix-ldap_3.7.11-0+deb12u1_ppc64el.deb 1337be5d1c24588165849046f1f8cf441241f0d0 19320 postfix-lmdb-dbgsym_3.7.11-0+deb12u1_ppc64el.deb b7fabbb4d8fedd005e87353f0dfaf0ce129099c6 339552 postfix-lmdb_3.7.11-0+deb12u1_ppc64el.deb 3c5ed213295fe70542ceaaa685e26e7bcd0a3d89 24024 postfix-mysql-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 979885678ea78d76419dbab5a6176af1b7a443e6 342368 postfix-mysql_3.7.11-0+deb12u1_ppc64el.deb d3e01ee49033c175c1592ed311c03052ea0351c2 15148 postfix-pcre-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 86ebdb943c962ee43e1102e28cb6afc7921e3dae 340564 postfix-pcre_3.7.11-0+deb12u1_ppc64el.deb 5ddea17d76cf488012c5d3310c0fda2ca2ecacd4 14208 postfix-pgsql-dbgsym_3.7.11-0+deb12u1_ppc64el.deb c35ac8183ddbd0e6c01ba7e6e9c3713af991122d 341176 postfix-pgsql_3.7.11-0+deb12u1_ppc64el.deb 747af48df8760d181e4c5a439152be65a55f1614 8636 postfix-sqlite-dbgsym_3.7.11-0+deb12u1_ppc64el.deb eb57b369625e2cb0e405fd565a20cf8b1ab01c14 337520 postfix-sqlite_3.7.11-0+deb12u1_ppc64el.deb 40d9f4c964ad5bc2a63144b0f9bf7200e732feb3 11821 postfix_3.7.11-0+deb12u1_ppc64el-buildd.buildinfo cbe8fc989efc5ab6179098ceae53b4d1deccb340 1753348 postfix_3.7.11-0+deb12u1_ppc64el.deb Checksums-Sha256: 12e3f10971fb37d492b8d1943a79efd2c2f87cd461262e373d2dae5435dca6b4 10892 postfix-cdb-dbgsym_3.7.11-0+deb12u1_ppc64el.deb a45cc95f2da59ed7be1cf44631214a4bc916d800eaa1092ae28f66dc9bc69a79 334152 postfix-cdb_3.7.11-0+deb12u1_ppc64el.deb 0a7d95fbb9e79175486ac106d12b15784880fdbb5a9873b679273ff0b1c2f133 1857032 postfix-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 21b3b5fb4947a43de6e194783384a2c002f5a6b52acf64d13d8ab22a0ba31c37 23264 postfix-ldap-dbgsym_3.7.11-0+deb12u1_ppc64el.deb e1589f67a85d017fe288bc0ad310af54589bed4b8f4a1e202cd1a9f8c2e5fa08 351504 postfix-ldap_3.7.11-0+deb12u1_ppc64el.deb 5525869d9ab1946d859a02dda46b1277e61221af5983f54966e3a057c57dec23 19320 postfix-lmdb-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 87e78c75912ae0cc49f2a24a9502f5e8a0d1450bf38f371b9b0a334db8b96f7f 339552 postfix-lmdb_3.7.11-0+deb12u1_ppc64el.deb a87d8a9451d2d4997d37234461aa77589d6917284f47f35bd314cd223109de06 24024 postfix-mysql-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 907ec180a11d2f39dd0349e1001b11868a23a8dd8d1c9de58bad8777cadab7e8 342368 postfix-mysql_3.7.11-0+deb12u1_ppc64el.deb 5ca79eb0b1f908cb23d746d1d7321906e8f1f8a24d223cefa813e16b57195d38 15148 postfix-pcre-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 1091f94746286761fca08d087d46e447b27ba0c1e4a3fa45c13c19855b1d1a48 340564 postfix-pcre_3.7.11-0+deb12u1_ppc64el.deb 83c86121dd59f2f3b52e97d332a46913260957bb1689d3413fe0832b363133cc 14208 postfix-pgsql-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 911cc6d9899265b48712035433cf2342cb709ef4ed6f7245fc5899e09c46abcd 341176 postfix-pgsql_3.7.11-0+deb12u1_ppc64el.deb 8aa31be8f0dced3da9861bbef2e2d65711d6f018fd68cae0190b92661861d7c1 8636 postfix-sqlite-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 98dabb74d3ae1e1867753c25a1d3214d614412ae48536ec5190a4de2a0f4be24 337520 postfix-sqlite_3.7.11-0+deb12u1_ppc64el.deb 2e3407af7daa570b89775aa7d931d8fc8d3cbbd3152146e67293a9099eea4a1c 11821 postfix_3.7.11-0+deb12u1_ppc64el-buildd.buildinfo 7e5af171a90df44ff94dfa1a2d4a35682845e55d187c2155004c66347e6074aa 1753348 postfix_3.7.11-0+deb12u1_ppc64el.deb Files: 8335ba2ba85b8e304073c1f2a9004607 10892 debug optional postfix-cdb-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 33d14b041fcdefcad783bfa847cdae93 334152 mail optional postfix-cdb_3.7.11-0+deb12u1_ppc64el.deb 9d071aab167d69c6770e1fb731d8b249 1857032 debug optional postfix-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 9f3a2db19a0d7fe8d5738eaf758080ee 23264 debug optional postfix-ldap-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 6c7b41ed62d37fb1b87508916c0fbf63 351504 mail optional postfix-ldap_3.7.11-0+deb12u1_ppc64el.deb 006c653378e812f8aa674eafcc6c830a 19320 debug optional postfix-lmdb-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 0dd3d7b3b26c0015ca22c09b8894eaa6 339552 mail optional postfix-lmdb_3.7.11-0+deb12u1_ppc64el.deb a7f714516a071dccbf2b7e6393204585 24024 debug optional postfix-mysql-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 6d0abd646921a1984fde9129bec7a0ec 342368 mail optional postfix-mysql_3.7.11-0+deb12u1_ppc64el.deb 7e2e13c2a41764117fdfff2f14f08d37 15148 debug optional postfix-pcre-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 921547e8138aa104e9b4b632433408bb 340564 mail optional postfix-pcre_3.7.11-0+deb12u1_ppc64el.deb c2475bdb7762b7d61221fe833757c05a 14208 debug optional postfix-pgsql-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 7c61c91dd2fdb747a55a332702109f88 341176 mail optional postfix-pgsql_3.7.11-0+deb12u1_ppc64el.deb b08fd27b43f2c6523d6d420f3a401ab9 8636 debug optional postfix-sqlite-dbgsym_3.7.11-0+deb12u1_ppc64el.deb 707312f61e6b1d0a630f38341fd6bc95 337520 mail optional postfix-sqlite_3.7.11-0+deb12u1_ppc64el.deb b40012028f0e630139ed7dd1c033e15f 11821 mail optional postfix_3.7.11-0+deb12u1_ppc64el-buildd.buildinfo 88781151564505786e6e9c326ed0d94e 1753348 mail optional postfix_3.7.11-0+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5hbnFkJlczvLwwS0Y7DdE4sWZ/UFAmYAooIACgkQY7DdE4sW Z/Umow//XzQv0RgxhTszBjheYi7BwOmKPZ2bxacbVOHXI1KD3bXPd1F9x4FDnMPp 930t1zeGi3mgkw/me1u7sUmXjif/D07dOYkqz3u9SgGCVR/WnN1M40wMBuURzjT7 cazpPNwnVt4b+Jf8KPYLVaslpDXaDO1W1c4mKL6uHlgvOpsDzdVXnzFZBNVt4mCd mtx3FQTOayrJk5yGtAf3p1oV8fXA5YSp8aWQIW8wuIqyASywapYIPmSla3hIyca+ kcRLe4WZp59Aw2vOpzJhJfO+kI54op/Dp+/iIVkEBtDqOOMoFAQl9AifPZhnPIBc JQ7NERYnlMZRlM8Jc6yIpJ19udi+h4srY0i9l9bMrpghQjzO654bpMir8eZXSamF ocyiqBMUiS96UE8Slbw+6gl8uax0+8Ycso/vPR20G303xZvDeGsnEWW9MyEvYpV0 q9u3JTt08rRZs6wAbwhpB0i3vt9HjHEl9w/Pt2l6VHoes7FIHi2bJmq5iCr22FU7 hLESMGL99qimOOQm3nVBgdGj8mvP+G42jQj5pHQGoZwNwF95xbjfy2mCj2xQQvFh 4B9u/TMLzvBzfKytSi5sQdsh4XO5CjMFN46mGUfUwsO/DVTOBoKsohr7uJP1Fe2k ZfM+jbNZwEXRf+Hca1OqBpvBYUClInDF8fQ0rWaMpLdf/JUMTfU= =n9QQ -----END PGP SIGNATURE-----