Changelog for
mutt-1.4.2.3-1tr.i586.rpm :
Thu Aug 9 14:00:00 2007 Nived Gopalan
1.4.2.3-1tr
- New Upstream.
- SECURITY Fix: A vulnerability has been reported in mutt, caused due
to a boundary error in the \"mutt_gecos_name()\" function when
processing \"&\" characters in the GECOS field. This can be exploited
to cause a buffer overflow during alias expansion.
- A weakness has been identified which is caused by an error in the
APOP protocol that fails to properly prevent MD5 collisions. This
could be exploited via man-in-the-middle attacks and specially
crafted message-IDs to potentially disclose the first three
characters of passwords.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CVE-2007-2683 and CVE-2007-1558 to these issue.
Mon Feb 26 13:00:00 2007 Nived Gopalan
- Rebuilt
Mon Oct 30 13:00:00 2006 Bipin S 1.4.2.1i-10tr
- SECURITY FIX: TAKAHASHI Tamotsu has reported a vulnerability in Mutt,
caused due to a boundary error within the \"browse_get_namespace()\"
function in browse.c. This can be exploited to cause a stack-based
buffer overflow when processing an overly long namespace from the
IMAP server.
- A race condition in the safe_open function, when
creating temporary files in an NFS filesystem, allows local users
to overwrite arbitrary files due to limitations of the use of the
O_EXCL flag on NFS filesystems.
- The mutt_adv_mktemp function does not properly verify that temporary
files that have been created with restricted permissions, which might
allow local users to create files with weak permissions via a race
condition between the mktemp and safe_fopen function calls.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CVE-2006-3242, CVE-2006-5297 and CVE-2006-5298 to
these issue.
Tue Apr 26 14:00:00 2005 Syed Shabir Zakiullah 1.4.2.1i-7tr
- Added gcc4 patch, Rebuilt against gcc-4.0
Fri Mar 18 13:00:00 2005 Lakshmi Dinamoni 1.4.2.1-6tr
- Rebuild for glibc-2.3.4-6tr
- Fix unpackaged files
Tue Mar 8 13:00:00 2005 Syed Shabir Zakiullah 1.4.2.1-5tr
- linked to gnutls, libgcrypt instead of OpenSSL
Tue Nov 9 13:00:00 2004 Oystein Vigge 1.4.2.1-4tr
- Rebuild with shared openssl
Wed Feb 18 13:00:00 2004 Omar Kilani 1.4.2.1-1ok
- New upstream.
Sun Dec 7 13:00:00 2003 Erlend Midttun 1.4.1-5tr
- Big rebuild
Wed Jun 18 14:00:00 2003 Erlend Midttun 1.4.1-4tr
- Big rebuild
Thu Jun 5 14:00:00 2003 Tore Olsen 1.4.1-3to
- Don\'t configure with --without-domain (it\'s the same as
--with-domain=no)
Fri May 23 14:00:00 2003 Tore Olsen 1.4.1i-2to
- removed locales
- added buildrequires openssl-devel
Mon May 12 14:00:00 2003 Erlend Midttun 1.4.1i-1em
- New upstream.
Mon Mar 24 13:00:00 2003 Erlend Midttun 1.4i-3em
- Rebuilt against glibc 2.3.2.
Sun Jan 19 13:00:00 2003 Gerald Dachs 1.41-2gd
- rebuilt against openssl 0.9.7
Tue Aug 13 14:00:00 2002 Christian H. Toldnes 1.4i-1ct
- New upstream version
Wed Jul 24 14:00:00 2002 Daniel Meyer 1.2.5i.1-3dm
- rebuild for Trustix Secure Linux 2.0
Mon Jun 3 14:00:00 2002 Erlend Midttun
- Now even use the %doc macro.
Thu Jan 3 13:00:00 2002 Erlend Midttun
- Picked up 1.2.5.1 to fix security hole.
Tue Jul 17 14:00:00 2001 Erlend Midttun
- Inc serial number before release.
Tue Mar 6 13:00:00 2001 Oystein Viggen
- Upgrade to v1.2.5i
Fri Nov 17 13:00:00 2000 Oystein Viggen
- Enable ssl support
Tue Jul 18 14:00:00 2000 Oystein Viggen
- Move man-pages to /usr/share/man
Fri Jul 7 14:00:00 2000 DindinX 1.2.4i-2mdk
- merge Geoffrey Lee\'s spec changes
- remove /etc/mimes.types from %files which caused a conflit w/ mailcap
Fri Jul 7 14:00:00 2000 Thierry Vignaud 1.2.4i-1mdk
- new release (This version fixes a couple of problems present in 1.2.2, and
one problem leading to crashes whose fix was missing from 1.2.3.)
Mon Jun 26 14:00:00 2000 DindinX 1.2.2i-3mdk
- put the Serial: tag back
Fri Jun 23 14:00:00 2000 DindinX 1.2.2i-2mdk
- fix the build as user the right way :)
Thu Jun 22 14:00:00 2000 Vincent Danen 1.2.2i-1mdk
- 1.2.2i
- removed %defattr which was causing readonly inboxes
- build with ncurses instead of slang to get colors working properly
- removed SSL support (won\'t compile due to keymaps bug)
- fixed build
Tue Jun 20 14:00:00 2000 Vincent Danen 1.2i-2mdk
- enable charmaps in configure
- removed --enable-compressed (no patch)
Mon Jun 19 14:00:00 2000 Vincent Danen 1.2i-1mdk
- 1.2i
- enable SSL and NFS fixes in configure
Thu Apr 27 14:00:00 2000 DindinX 1.0.1i-7mdk
- Recompile fix.
- fix the color scheme.
Wed Apr 5 14:00:00 2000 Chmouel Boudjnah 1.0.1i-6mdk
- By default active colors.
- Believe me or not, fix menu and %post.
- Use find_lang macros for locales.
Tue Apr 4 14:00:00 2000 Chmouel Boudjnah 1.0.1i-5mdk
- Fix another chmousucks in menu (yes me too i can believe it).
Mon Apr 3 14:00:00 2000 Chmouel Boudjnah 1.0.1i-4mdk
- Fix chmousucks in menu.
- Add icons in menu.
Fri Mar 31 14:00:00 2000 Chmouel Boudjnah 1.0.1i-3mdk
- Fix menu entry (don\'t only cp the meny entry from your debian box
dindin ;)).
Fri Mar 24 13:00:00 2000 DindinX 1.0.1i-2mdk
- Specs and group fixes
- Added menu support
Sun Feb 6 13:00:00 2000 Andre Steden
- 1.0.1
- add compressed folders patch
- add colour patch
Sat Nov 6 13:00:00 1999 John Buswell
- Build Release
Thu Oct 28 14:00:00 1999 Chmouel Boudjnah
- 1.0.
Wed Oct 6 14:00:00 1999 Chmouel Boudjnah
- 1.0pre3.
Mon Aug 9 14:00:00 1999 Daouda LO
-0.95.7
-added manual.sgml in documents.
Sun May 9 14:00:00 1999 Chmouel Boudjnah
- Fix bug of locales.
Wed Apr 28 14:00:00 1999 Chmouel Boudjnah
- Mandrake adaptations.
- update to 0.99.5.
Mon Mar 8 13:00:00 1999 Bill Nottingham
- update to 0.95.4 - fixes a /tmp race
Wed Feb 24 13:00:00 1999 Bill Nottingham
- the RETURN OF WMCONFIG! Aiyeee!
Fri Feb 12 13:00:00 1999 Bill Nottingham
- 0.95.3 - fixes mailcap handling
Mon Jan 4 13:00:00 1999 Bill Nottingham
- 0.95.1
Sat Dec 12 13:00:00 1998 Bill Nottingham
- 0.95
Fri Jul 31 14:00:00 1998 Bill Nottingham
- backport some 0.94.2 security fixes
- fix un-setgid
- update to 0.93.2
Tue Jul 28 14:00:00 1998 Jeff Johnson
- security fix
- update to 0.93.1.
- turn off setgid mail.
Thu May 7 14:00:00 1998 Prospector System
- translations modified for de, fr, tr
Tue Apr 21 14:00:00 1998 Cristian Gafton
- updated to 0.91.1
Fri Apr 10 14:00:00 1998 Cristian Gafton
- updated to mutt-0.89.1
Thu Oct 16 14:00:00 1997 Otto Hammersmith
- Updated to mutt 0.85.
- added wmconfig entries.
- removed mime.types
Mon Sep 1 14:00:00 1997 Donnie Barnes
- Rebuilt to insure all sources were fresh and patches were clean.
Wed Aug 6 14:00:00 1997 Manoj Kasichainula
- Initial version for 0.81(e)