From: Jeremy Harris Date: Tue, 28 Nov 2017 20:44:14 +0000 (+0000) Subject: Change log update X-Git-Tag: exim-4_91_RC1~148^2~20 X-Git-Url: https://vcs.fsf.org/?p=exim.git;a=commitdiff_plain;h=e066e10220ab267cb88339789a67e28ec65b0e5b;hp=527504e8d8ff7a1cd967ea57cb7f29b92b052bae Change log update --- diff --git a/doc/doc-txt/ChangeLog b/doc/doc-txt/ChangeLog index 0dd8ca60f..fcd5e691f 100644 --- a/doc/doc-txt/ChangeLog +++ b/doc/doc-txt/ChangeLog @@ -203,7 +203,11 @@ JH/33 Downgrade an unfound-list name (usually a typo in the config file) from JH/34 Bug 2199: Fix a use-after-free while reading smtp input for header lines. A crafted sequence of BDAT commands could result in in-use memory beeing - freed. + freed. CVE-2017-16943. + +HS/03 Bug 2201: Fix checking for leading-dot on a line during headers reading + from SMTP input. Previously it was always done; now only done for DATA + and not BDAT commands. CVE-2017-16944. Exim version 4.89