Re: HEADS UP package "fetchmail" vulnerable and 6.4.0 release candidate out

2019-08-28 Thread Corinna Vinschen
Hi Matthias, On Aug 20 19:49, Matthias Andree wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Corinna, and everyone else who is interested, > > checking , > I see that Cygwin packages a very old fetchmail version that has unfi

Re: HEADS UP package "fetchmail" vulnerable and 6.4.0 release candidate out

2019-08-21 Thread Achim Gratz
Matthias Andree writes: > 3. Please try to package 6.4.0.rc2 for x86 and x86_64 against Cygwin's > libssl1.1, and see if you find any portability issues that would require > fixing before 6.4.0. Deadline end of August 2019, and unless really > needed for non-trivial code changes, rc2 is also the pl

HEADS UP package "fetchmail" vulnerable and 6.4.0 release candidate out

2019-08-20 Thread Matthias Andree
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Corinna, and everyone else who is interested, checking , I see that Cygwin packages a very old fetchmail version that has unfixed security vulnerabilities and unfixed critical (data loss) bugs.