Merge branch 'debian' stretch
authorClinton Ebadi <clinton@unknownlamer.org>
Fri, 6 Sep 2019 18:23:36 +0000 (14:23 -0400)
committerClinton Ebadi <clinton@unknownlamer.org>
Fri, 6 Sep 2019 18:23:36 +0000 (14:23 -0400)
1  2 
debian/changelog
debian/patches/series

diff --combined debian/changelog
@@@ -1,9 -1,17 +1,29 @@@
++exim4 (4.89-2+deb9u6~hcoop11) unstable; urgency=medium
++
++  * New upstream security release
++
++ -- Clinton Ebadi <clinton@unknownlamer.org>  Fri, 06 Sep 2019 14:23:08 -0400
++
+ exim4 (4.89-2+deb9u6) stretch-security; urgency=high
+   * 85_01-string.c-do-not-interpret-before-0-CVE-2019-15846.patch Fix SNI
+     related buffer overflow. CVE-2019-15846
+  -- Andreas Metzler <ametzler@debian.org>  Tue, 03 Sep 2019 20:01:38 +0200
+ exim4 (4.89-2+deb9u5) stretch-security; urgency=high
+   * Fix remote command execution vulnerability related to
+     "${sort}"-expansion. CVE-2019-13917 OVE-20190718-0006
+  -- Andreas Metzler <ametzler@debian.org>  Sat, 20 Jul 2019 13:32:35 +0200
 +exim4 (4.89-2+deb9u4~hcoop10) unstable; urgency=medium
 +
 +  * Rebuild on 4.89-2+deb9u4
 +
 + -- Clinton Ebadi <clinton@unknownlamer.org>  Thu, 06 Jun 2019 19:35:28 -0400
 +
  exim4 (4.89-2+deb9u4) stretch-security; urgency=high
  
    * Non-maintainer upload by the Security Team.
@@@ -725,30 -733,6 +745,30 @@@ exim4 (4.85~RC1+dfsg-1) experimental; u
  
   -- Andreas Metzler <ametzler@debian.org>  Tue, 18 Nov 2014 19:28:20 +0100
  
 +exim4 (4.84-8+hcoop4) unstable; urgency=medium
 +
 +  * Missed another chown that needs skipping
 +
 + -- Clinton Ebadi <clinton@unknownlamer.org>  Thu, 14 May 2015 01:35:09 -0400
 +
 +exim4 (4.84-8+hcoop3) unstable; urgency=medium
 +
 +  * Patch the right thing.
 +
 + -- Clinton Ebadi <clinton@unknownlamer.org>  Thu, 14 May 2015 00:34:14 -0400
 +
 +exim4 (4.84-8+hcoop2) unstable; urgency=medium
 +
 +  * Change message in chown failure for sanity check
 +
 + -- Clinton Ebadi <clinton@unknownlamer.org>  Wed, 13 May 2015 23:47:18 -0400
 +
 +exim4 (4.84-8+hcoop1) unstable; urgency=medium
 +
 +  * Relax chown requirement for delivery into afs
 +
 + -- Clinton Ebadi <clinton@unknownlamer.org>  Wed, 13 May 2015 23:26:54 -0400
 +
  exim4 (4.84-8) unstable; urgency=medium
  
    * Pull 83_Remove-limit-on-remove_headers-item-size.-Bug-1533.patch and
diff --combined debian/patches/series
@@@ -5,7 -5,6 +5,7 @@@
  35_install.dpatch
  40_reproducible_build.diff
  50_localscan_dlopen.dpatch
 +50-relax-appendfile-chown-openafs.patch
  60_convert4r4.dpatch
  67_unnecessaryCopt.diff
  70_remove_exim-users_references.dpatch
@@@ -15,3 -14,5 +15,5 @@@
  81_Chunking-do-not-treat-the-first-lonely-dot-special.-.patch
  82_Fix-base64d-buffer-size-CVE-2018-6789.patch
  83_qsa-2019-exim4.patch
+ 84_Avoid-re-expansion-in-sort-CVE-2019-13917-OVE-201907.patch
+ 85_01-string.c-do-not-interpret-before-0-CVE-2019-15846.patch