[SECURITY] Fedora 19 Update: ssmtp-2.64-9.fc19

updates at fedoraproject.org updates at fedoraproject.org
Fri Aug 30 22:59:08 UTC 2013


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2013-15049
2013-08-20 22:21:05
--------------------------------------------------------------------------------

Name        : ssmtp
Product     : Fedora 19
Version     : 2.64
Release     : 9.fc19
URL         : http://packages.debian.org/stable/mail/ssmtp
Summary     : Extremely simple MTA to get mail off the system to a Mailhub
Description :
A secure, effective and simple way of getting mail off a system to your mail
hub. It contains no suid-binaries or other dangerous things - no mail spool
to poke around in, and no daemons running in the background. Mail is simply
forwarded to the configured mailhost. Extremely easy configuration.

WARNING: the above is all it does; it does not receive mail, expand aliases
or manage a queue. That belongs on a mail hub with a system administrator.

--------------------------------------------------------------------------------
Update Information:

Use a corrected patch to validate server certificates
Removes world read access from the configuration file thus prohibiting reading of password stored inside it.
Removes world read access from the configuration file thus prohibiting reading of password stored inside it.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Aug 20 2013 Manuel "lonely wolf" Wolfshant <wolfy at fedoraproject.org> - 2.64-9
- replace TLS patch with a corrected one. thanks Till Maas for the fix
* Sun Aug  4 2013 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 2.64-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
* Wed Jun  5 2013 Manuel "lonely wolf" Wolfshant <wolfy at fedoraproject.org> - 2.64-7
- remove world readable permissions of the config file (#962988)
- revive the authpass patch (#970123)
- revive improved default config settings which were lost during rebase (#895708)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #864894 - ssmtp: Does not validate server certificates when using TLS connection
        https://bugzilla.redhat.com/show_bug.cgi?id=864894
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update ssmtp' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list