-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 09 Mar 2024 10:38:51 -0500 Source: postfix Binary: postfix postfix-cdb postfix-cdb-dbgsym postfix-dbgsym postfix-ldap postfix-ldap-dbgsym postfix-lmdb postfix-lmdb-dbgsym postfix-mysql postfix-mysql-dbgsym postfix-pcre postfix-pcre-dbgsym postfix-pgsql postfix-pgsql-dbgsym postfix-sqlite postfix-sqlite-dbgsym Architecture: s390x Version: 3.5.25-0+deb11u1 Distribution: bullseye Urgency: medium Maintainer: s390x Build Daemon (zani) Changed-By: Scott Kitterman Description: postfix - High-performance mail transport agent postfix-cdb - CDB map support for Postfix postfix-ldap - LDAP map support for Postfix postfix-lmdb - LMDB map support for Postfix postfix-mysql - MySQL map support for Postfix postfix-pcre - PCRE map support for Postfix postfix-pgsql - PostgreSQL map support for Postfix postfix-sqlite - SQLite map support for Postfix Changes: postfix (3.5.25-0+deb11u1) bullseye; urgency=medium . [Wietse Venema] . * 3.5.25 - Bugfix (defect introduced: Postfix 2.3, date 20051222): the Dovecot auth client did not reset the 'reason' from a previous Dovecot auth service response, before parsing the next Dovecot auth server response in the same SMTP session. Reported by Stephan Bosch, File: xsasl/xsasl_dovecot_server.c. - Cleanup: Postfix SMTP server response with an empty authentication failure reason. File: smtpd/smtpd_sasl_glue.c. - Bugfix (defect introduced: Postfix 3.1, date: 20151128): "postqueue -j" produced broken JSON when escaping a control character as \uXXXX. Found during code maintenance. File: postqueue/showq_json.c. - Cleanup: posttls-finger certificate match expectations for all TLS security levels, including warnings for levels that don't implement certificate matching. Viktor Dukhovni. File: posttls-finger.c. - Bugfix (defect introduced: Postfix 2.3): after prepending a message header with a Postfix access table PREPEND action, a Milter request to delete or update an existing header could have no effect, or it could target the wrong instance of an existing header. Root cause: the fix dated 20141018 for the Postfix Milter client was incomplete. The client did correctly hide the first, Postfix-generated, Received: header when sending message header information to a Milter with the smfi_header() application callback function, but it was still hiding the first header (instead of the first Received: header) when handling requests from a Milter to delete or update an existing header. Problem report by Carlos Velasco. This change was verified to have no effect on requests from a Milter to add or insert a header. File: cleanup/cleanup_milter.c. - Workaround: tlsmgr logfile spam. Some OS lies under load: it says that a socket is readable, then it says that the socket has unread data, and then it says that read returns EOF, causing Postfix to spam the log with a warning message. File: tlsmgr/tlsmgr.c. - Bugfix (defect introduced: Postfix 3.4): the SMTP server's BDAT command handler could be tricked to read $message_size_limit bytes into memory. Found during code maintenance. File: smtpd/smtpd.c. - Performance: eliminate worst-case behavior where the queue manager defers delivery to all destinations over a specific delivery transport, after only a single delivery agent failure. The scheduler now throttles one destination, and allows deliveries to other destinations to keep making progress. Files: *qmgr/qmgr_deliver.c. - Safety: drop and log over-size DNS responses resulting in more than 100 records. This 20x larger than the number of server addresses that the Postfix SMTP client is willing to consider when delivering mail, and is well below the number of records that could cause a tail recursion crash in dns_rr_append() as reported by Toshifumi Sakaguchi. This also limits the number of DNS requests from check_*_*_access restrictions. Files: dns/dns.h, dns/dns_lookup.c, dns/dns_rr.c, dns/test_dns_lookup.c, posttls-finger/posttls-finger.c, smtp/smtp_addr.c, smtpd/smtpd_check.c. Checksums-Sha1: b2fe93202342e9b04a097cb169feb0a97ee64031 9780 postfix-cdb-dbgsym_3.5.25-0+deb11u1_s390x.deb 38b4e9c1730d2924c68c6dc95b1e6159ccefd071 364504 postfix-cdb_3.5.25-0+deb11u1_s390x.deb e1577b642eb6aa9aaef8e3136675acd96d91fc7b 2094352 postfix-dbgsym_3.5.25-0+deb11u1_s390x.deb bb50dabeffdb73e6f5be55dd632a1e60d6272f96 21552 postfix-ldap-dbgsym_3.5.25-0+deb11u1_s390x.deb b5903f7d8dfaa5fb608f724d6f242887ccd9baff 382080 postfix-ldap_3.5.25-0+deb11u1_s390x.deb 1735d8eb9829d56da871fc5653997d362b37e318 18408 postfix-lmdb-dbgsym_3.5.25-0+deb11u1_s390x.deb 28ce79f775e392822d7a0de42f9f5690366a5235 370256 postfix-lmdb_3.5.25-0+deb11u1_s390x.deb 474734621ea5768da43dd50b8b7406878174e9e3 23312 postfix-mysql-dbgsym_3.5.25-0+deb11u1_s390x.deb 34da8aac5fa97ebf0f5b7a0d9f388389b7345d5e 372080 postfix-mysql_3.5.25-0+deb11u1_s390x.deb 60161b0b489e6684967bc96ad10c94f8992b4a3c 13964 postfix-pcre-dbgsym_3.5.25-0+deb11u1_s390x.deb a41f06f9f87209fc6a9233ef600754ddbd673e78 370036 postfix-pcre_3.5.25-0+deb11u1_s390x.deb 35d41a7713f0a4f136ba3b3b5bf6792740ada9c1 13068 postfix-pgsql-dbgsym_3.5.25-0+deb11u1_s390x.deb baeb24d68cc93c4ec50b44528bc29619d2dbbfad 370876 postfix-pgsql_3.5.25-0+deb11u1_s390x.deb 2cf8dfed7bb696e3ead3528ac110ccf1980a35dc 7616 postfix-sqlite-dbgsym_3.5.25-0+deb11u1_s390x.deb 3e38ea7924d9bf166b59ecc17728fac935853422 367964 postfix-sqlite_3.5.25-0+deb11u1_s390x.deb 191f5439be902f9eb503e3eecc99736cc2bc4261 12100 postfix_3.5.25-0+deb11u1_s390x-buildd.buildinfo 73c31dbc65050c297b89f58ba9de14b878036754 1508984 postfix_3.5.25-0+deb11u1_s390x.deb Checksums-Sha256: b76f23ecee50a9d4c630cd8af7664506baeb178a1c6ce632edd6c82303bd8ed4 9780 postfix-cdb-dbgsym_3.5.25-0+deb11u1_s390x.deb 8ea255ac339b0c9f826943cbb60aaa54d87a8ebf9975e47b1a50b2a76a39f776 364504 postfix-cdb_3.5.25-0+deb11u1_s390x.deb e665f41521cdb4fd30ac0462b0cca4cb2ed3b4684a3482a45b9285e872b474c7 2094352 postfix-dbgsym_3.5.25-0+deb11u1_s390x.deb 7905d0544522064f3c034ee2ad985aeb8a73c772ca61cffdaf5927df7f4dc46a 21552 postfix-ldap-dbgsym_3.5.25-0+deb11u1_s390x.deb 12c6f82ec9d0909aba0b8a9d71666c896ab9a8b1e61ba503463fddb0bbd34bf6 382080 postfix-ldap_3.5.25-0+deb11u1_s390x.deb f67a5bff29e4e0a34d06a3270f1ec77281d39db6f6238776c25b4bf59aa555c1 18408 postfix-lmdb-dbgsym_3.5.25-0+deb11u1_s390x.deb 82a98b3e9527bfb81476b3ea5cbd567c8df92c292adf3ea3909404672056dacc 370256 postfix-lmdb_3.5.25-0+deb11u1_s390x.deb 36543642cef0662c308d26b5b11bbcc273dec00ed1b58148cfabbdfc2ae78d69 23312 postfix-mysql-dbgsym_3.5.25-0+deb11u1_s390x.deb b019803477396b586bab674ccef653776899435bfefd6eebc803a078f936fd41 372080 postfix-mysql_3.5.25-0+deb11u1_s390x.deb 616a1c66eb652024de0e976c487c9063c06f2db59b66bc0a617dbb9155613bfe 13964 postfix-pcre-dbgsym_3.5.25-0+deb11u1_s390x.deb 3deae0b808b733bda646ca8a37149edf6ebadf9379c98cf3f2142a05c4c033ea 370036 postfix-pcre_3.5.25-0+deb11u1_s390x.deb 9e1513dbd575e58ddd2fd115fc772c0e2d61edfd4f60885c8f124c6c5eb4bbcf 13068 postfix-pgsql-dbgsym_3.5.25-0+deb11u1_s390x.deb 8d2406bf9db0315584b2cea1bb68cf8ceaca060c8cd139174337ab53b61cfa24 370876 postfix-pgsql_3.5.25-0+deb11u1_s390x.deb 5437a0dc24319be49121f4c9398e3e364643c6818a626d557aa39ef5a66f1501 7616 postfix-sqlite-dbgsym_3.5.25-0+deb11u1_s390x.deb c64c24a07214d8bf0c1e8f8a6eb11ba34459939200332ad7bffbd7e73d700623 367964 postfix-sqlite_3.5.25-0+deb11u1_s390x.deb 37f9f93358d0fc0c8624aa31b338d1737ec69d528087223b25198611a5a446f9 12100 postfix_3.5.25-0+deb11u1_s390x-buildd.buildinfo 2636fdf7bd56d783387b0b71bc168afd0396d1a2f846098248e7f78af46ee24c 1508984 postfix_3.5.25-0+deb11u1_s390x.deb Files: 600814ef1b56394524fa43b7ae5e22a9 9780 debug optional postfix-cdb-dbgsym_3.5.25-0+deb11u1_s390x.deb 0c01695b99784f50e7e2c486981a2a5d 364504 mail optional postfix-cdb_3.5.25-0+deb11u1_s390x.deb 6260aa4a7a9fea65525f4bfba1d0d5a7 2094352 debug optional postfix-dbgsym_3.5.25-0+deb11u1_s390x.deb 267faffec4a6307906e4a012f091135d 21552 debug optional postfix-ldap-dbgsym_3.5.25-0+deb11u1_s390x.deb 5e6158bc10ebffc6efaae495a8b28bb6 382080 mail optional postfix-ldap_3.5.25-0+deb11u1_s390x.deb f7887e05243ee57f2b6c3952f0eb9652 18408 debug optional postfix-lmdb-dbgsym_3.5.25-0+deb11u1_s390x.deb ce564021cfff064bb19f6eea93efeb37 370256 mail optional postfix-lmdb_3.5.25-0+deb11u1_s390x.deb 59428a6b0fd4663a1c6376c4f91d9cb7 23312 debug optional postfix-mysql-dbgsym_3.5.25-0+deb11u1_s390x.deb af08518aaef2b9899d06b031095e2a01 372080 mail optional postfix-mysql_3.5.25-0+deb11u1_s390x.deb bdded6e703f50f3902a1c5aa81cdd133 13964 debug optional postfix-pcre-dbgsym_3.5.25-0+deb11u1_s390x.deb 9e9e365037158594962a38ba4a1d7c21 370036 mail optional postfix-pcre_3.5.25-0+deb11u1_s390x.deb 1cda57a2578b56b5f7793ea53fe763b0 13068 debug optional postfix-pgsql-dbgsym_3.5.25-0+deb11u1_s390x.deb 7be257c0217852f22caafe134c1eefa8 370876 mail optional postfix-pgsql_3.5.25-0+deb11u1_s390x.deb 029b0460cfb791ac7463b5851bcf5a45 7616 debug optional postfix-sqlite-dbgsym_3.5.25-0+deb11u1_s390x.deb 40463616f04e56369f5a857f5b1a2673 367964 mail optional postfix-sqlite_3.5.25-0+deb11u1_s390x.deb bc758101c1734610ebb8fecb42202345 12100 mail optional postfix_3.5.25-0+deb11u1_s390x-buildd.buildinfo dedc5d4751400eab40111719cb331ebe 1508984 mail optional postfix_3.5.25-0+deb11u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEETdQgQHyJW2hcXsTC6b+AMjGgQHgFAmYm0JsACgkQ6b+AMjGg QHgXNhAAgEr4FJO03wLbx0GkOXkJmzcfDa2yF+w5xdqFemtHADzAkd0qP3O4336m 3zGVjLi/CQAKFgp0sUQQ5awAgw19KpQOw0e8AG6ul4K2hgNCoBDq94WtQtFd58p9 cu7ZiwxERkYbh9mp385C6+IfIBDnRV1eJq+YSGVWkMwPnDfcGearr5SSa5DV+1Tb fxJ1I4JOi5U3/1ksNhTioRkFXa0amedRxwwAdgY3oalcjQcRJ+39+UoHuKcWhfV2 QxjdH2ARLmvla0LWOCW3eZd92sixUW06BmjikB/66KZKRNaGPtMA7ztaFFDNFhDB +XqxOdaDzeFmZfiSFXX3mWEXPoYU2G+GhtnRS2ujlnZmQOK7qxr2eEosmSQWQ/qA 3QPZ2OpT1FSGRyJO5ns83DAouoTNLy3wEH4UOfUJ6XVEUFcxUjD9B/gTZeVMsCgu VdmQrnCV7TJ5vFEBc5kzKsgCNvjzw+0Rn3OstBCclyx6m+zvTbx+BbDQWIGDQpvp J7DFXlSCHSfBsjmrqMzfaNh9AqYBv324brxExeldRgsInt70XfgMkgrfCmzhRajp Opg95Nz7U9Z/yX8vpv4sOAeoDjkpJlQRVPkbMpY9ZeLF3G/JYUnOXfnQChBwpk3P uJ2/ytuwWhkKYVbHFPBTcO3PybyTRgfATeKr7cmSdXBAIFOzDOs= =GkFh -----END PGP SIGNATURE-----