mirror of
https://github.com/gentoo-mirror/gentoo.git
synced 2026-09-24 04:59:14 -07:00
mail-mta/exim: add patch for CVE-2017-16943, bug #638772
Bug: https://bugs.gentoo.org/638772 Package-Manager: Portage-2.3.13, Repoman-2.3.3
This commit is contained in:
@@ -1,3 +1,3 @@
|
||||
DIST exim-4.89.tar.bz2 1844430 SHA256 912f2ee03c8dba06a3a4c0ee40522d367e1b65dc59e38dfcc1f5d9eecff51ab0 SHA512 1e059966a93b47f055ab4ec2a4556f2c918aff56ea0367585f3a853f00411e9c275e13be4f9ae615a468fa06263135cd6a138fa1753f1b7fb3259a3321fcca65 WHIRLPOOL d0b30cde5cf2dbe278d393eae70e40a3861a153a2411f98f73a7ae43881032cc3e0f15163b09e17d61c09e673c2e766371c80533908af3460f483a5c18dff80f
|
||||
DIST exim-pdf-4.89.tar.bz2 1924606 SHA256 17d70ef5b2814f725633efcf339bcb49ac9564ecd648e0e3d010b5e43d6c167d SHA512 b04ea2e4dcdb1aaf52ef77ccd76e6599c68c4c6e5a98090720dbd3c50f7191bf3f6cd7dc2089a765c47576311780809cff547f85f004caec411d0f1ac9985299 WHIRLPOOL 4ab5bc7bdbbfc998ae7ee63f19449d051a1d7183f9b70297db100f44b82df2cca0853c309ddfccafee2d44cd1228258e06628ed82dab76de851bec856321c58f
|
||||
DIST system_filter.exim.gz 3075 SHA256 3a3471b486a09e0a0153f7b520e1eaf26d21b97d73ea8348bdc593c00eb1e437 SHA512 cb358d3ce2499a0bb5920d962a06f2af8486e55ec90c8c928bd8e3aefb279aa57f5f960d5adfcef68bd94110b405eaa144e9629cfe6014a529c79c544600bbf3 WHIRLPOOL ce68d9c18b24eca3ef97ea810964cc1ada5f85b795a7c432ad39b5788188a16419101c92fb52b418738d760e1d658f7a41485e5561079a667d84d276c71be5a4
|
||||
DIST exim-4.89.tar.bz2 1844430 BLAKE2B 255bb3f27a264d92bf4664cf1278beabffa888006dfc0b31cde8a04d62501b0fe282db5b959bd303e2a818322716548c97264842130b8d5c3b9075615f668ca7 SHA512 1e059966a93b47f055ab4ec2a4556f2c918aff56ea0367585f3a853f00411e9c275e13be4f9ae615a468fa06263135cd6a138fa1753f1b7fb3259a3321fcca65
|
||||
DIST exim-pdf-4.89.tar.bz2 1924606 BLAKE2B f03182d51f4cc5b71cb65c2e0bcf74142f8110b6bfbd5b0fc05e321b692ebde5dbc84c4562a39ee85065f4d2db0654e6a189c826bfdea19051f56969d4ca74e2 SHA512 b04ea2e4dcdb1aaf52ef77ccd76e6599c68c4c6e5a98090720dbd3c50f7191bf3f6cd7dc2089a765c47576311780809cff547f85f004caec411d0f1ac9985299
|
||||
DIST system_filter.exim.gz 3075 BLAKE2B d05e872b5cef377d29126cda03fc0a74c8777b2119b76ff43da6e8de808035eb9bfcb034a85d81824f135d484e864bfc0629fc1af2c228a7277d5ee7cf9cde79 SHA512 cb358d3ce2499a0bb5920d962a06f2af8486e55ec90c8c928bd8e3aefb279aa57f5f960d5adfcef68bd94110b405eaa144e9629cfe6014a529c79c544600bbf3
|
||||
|
||||
531
mail-mta/exim/exim-4.89-r4.ebuild
Normal file
531
mail-mta/exim/exim-4.89-r4.ebuild
Normal file
@@ -0,0 +1,531 @@
|
||||
# Copyright 1999-2017 Gentoo Foundation
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
EAPI="6"
|
||||
|
||||
inherit eutils toolchain-funcs multilib pam systemd
|
||||
|
||||
IUSE="dane dcc +dkim dlfunc dmarc +dnsdb doc dovecot-sasl dsn exiscan-acl gnutls ipv6 ldap libressl lmtp maildir mbx mysql nis pam perl pkcs11 postgres +prdr proxy radius redis sasl selinux spf sqlite srs ssl syslog tcpd tpda X elibc_glibc"
|
||||
REQUIRED_USE="
|
||||
dane? ( !gnutls )
|
||||
dmarc? ( spf dkim )
|
||||
pkcs11? ( gnutls )
|
||||
spf? ( exiscan-acl )
|
||||
srs? ( exiscan-acl )
|
||||
"
|
||||
|
||||
COMM_URI="ftp://ftp.exim.org/pub/exim/exim4$([[ ${PV} == *_rc* ]] && echo /test)"
|
||||
|
||||
DESCRIPTION="A highly configurable, drop-in replacement for sendmail"
|
||||
SRC_URI="${COMM_URI}/${P//rc/RC}.tar.bz2
|
||||
mirror://gentoo/system_filter.exim.gz
|
||||
doc? ( ${COMM_URI}/${PN}-pdf-${PV//rc/RC}.tar.bz2 )"
|
||||
HOMEPAGE="http://www.exim.org/"
|
||||
|
||||
SLOT="0"
|
||||
LICENSE="GPL-2"
|
||||
KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86 ~x86-fbsd ~x86-solaris"
|
||||
|
||||
COMMON_DEPEND=">=sys-apps/sed-4.0.5
|
||||
>=sys-libs/db-3.2:=
|
||||
dev-libs/libpcre
|
||||
perl? ( dev-lang/perl:= )
|
||||
pam? ( virtual/pam )
|
||||
tcpd? ( sys-apps/tcp-wrappers )
|
||||
ssl? (
|
||||
!libressl? ( dev-libs/openssl:0= )
|
||||
libressl? ( dev-libs/libressl:= )
|
||||
)
|
||||
gnutls? ( net-libs/gnutls[pkcs11?]
|
||||
dev-libs/libtasn1 )
|
||||
ldap? ( >=net-nds/openldap-2.0.7 )
|
||||
nis? ( elibc_glibc? ( || (
|
||||
<sys-libs/glibc-2.23
|
||||
>=sys-libs/glibc-2.23[rpc]
|
||||
) ) )
|
||||
mysql? ( virtual/libmysqlclient )
|
||||
postgres? ( dev-db/postgresql:= )
|
||||
sasl? ( >=dev-libs/cyrus-sasl-2.1.26-r2 )
|
||||
redis? ( dev-libs/hiredis )
|
||||
spf? ( >=mail-filter/libspf2-1.2.5-r1 )
|
||||
dmarc? ( mail-filter/opendmarc )
|
||||
srs? ( mail-filter/libsrs_alt )
|
||||
X? ( x11-proto/xproto
|
||||
x11-libs/libX11
|
||||
x11-libs/libXmu
|
||||
x11-libs/libXt
|
||||
x11-libs/libXaw
|
||||
)
|
||||
sqlite? ( dev-db/sqlite )
|
||||
radius? ( net-dialup/freeradius-client )
|
||||
virtual/libiconv
|
||||
"
|
||||
# added X check for #57206
|
||||
DEPEND="${COMMON_DEPEND}
|
||||
virtual/pkgconfig"
|
||||
RDEPEND="${COMMON_DEPEND}
|
||||
!mail-mta/courier
|
||||
!mail-mta/esmtp
|
||||
!mail-mta/mini-qmail
|
||||
!<mail-mta/msmtp-1.4.19-r1
|
||||
!>=mail-mta/msmtp-1.4.19-r1[mta]
|
||||
!mail-mta/netqmail
|
||||
!mail-mta/nullmailer
|
||||
!mail-mta/postfix
|
||||
!mail-mta/qmail-ldap
|
||||
!mail-mta/sendmail
|
||||
!mail-mta/opensmtpd
|
||||
!<mail-mta/ssmtp-2.64-r2
|
||||
!>=mail-mta/ssmtp-2.64-r2[mta]
|
||||
!net-mail/mailwrapper
|
||||
>=net-mail/mailbase-0.00-r5
|
||||
virtual/logger
|
||||
dcc? ( mail-filter/dcc )
|
||||
selinux? ( sec-policy/selinux-exim )
|
||||
"
|
||||
|
||||
S=${WORKDIR}/${P//rc/RC}
|
||||
|
||||
src_prepare() {
|
||||
epatch "${FILESDIR}"/exim-4.14-tail.patch
|
||||
epatch "${FILESDIR}"/exim-4.74-localscan_dlopen.patch
|
||||
epatch "${FILESDIR}"/exim-4.69-r1.27021.patch
|
||||
epatch "${FILESDIR}"/exim-4.74-radius-db-ENV-clash.patch # 287426
|
||||
epatch "${FILESDIR}"/exim-4.82-makefile-freebsd.patch # 235785
|
||||
epatch "${FILESDIR}"/exim-4.89-as-needed-ldflags.patch # 352265, 391279
|
||||
epatch "${FILESDIR}"/exim-4.76-crosscompile.patch # 266591
|
||||
epatch "${FILESDIR}"/exim-4.89-CVE-2017-1000369.patch # 622212
|
||||
epatch "${FILESDIR}"/${P}-transport-crash.patch # from git/in next release
|
||||
epatch "${FILESDIR}"/${P}-address-expando-crash.patch # from git/in next release
|
||||
epatch "${FILESDIR}"/${P}-CVE-2017-16943.patch # from git/in next release
|
||||
|
||||
if use maildir ; then
|
||||
epatch "${FILESDIR}"/exim-4.20-maildir.patch
|
||||
else
|
||||
epatch "${FILESDIR}"/exim-4.80-spool-mail-group.patch # 438606
|
||||
fi
|
||||
|
||||
eapply_user
|
||||
|
||||
# user Exim believes it should be
|
||||
MAILUSER=mail
|
||||
MAILGROUP=mail
|
||||
if use prefix && [[ ${EUID} != 0 ]] ; then
|
||||
MAILUSER=$(id -un)
|
||||
MAILGROUP=$(id -gn)
|
||||
fi
|
||||
}
|
||||
|
||||
src_configure() {
|
||||
# general config and paths
|
||||
|
||||
sed -i.orig \
|
||||
-e "/SYSTEM_ALIASES_FILE/s'SYSTEM_ALIASES_FILE'${EPREFIX}/etc/mail/aliases'" \
|
||||
"${S}"/src/configure.default || die
|
||||
|
||||
sed -i -e 's/^buildname=.*/buildname=exim-gentoo/g' Makefile || die
|
||||
|
||||
sed -e "48i\CFLAGS=${CFLAGS}" \
|
||||
-e "s:BIN_DIRECTORY=/usr/exim/bin:BIN_DIRECTORY=${EPREFIX}/usr/sbin:" \
|
||||
-e "s:EXIM_USER=:EXIM_USER=${MAILUSER}:" \
|
||||
-e "s:CONFIGURE_FILE=/usr/exim/configure:CONFIGURE_FILE=${EPREFIX}/etc/exim/exim.conf:" \
|
||||
-e "s:ZCAT_COMMAND=.*$:ZCAT_COMMAND=${EPREFIX}/bin/zcat:" \
|
||||
-e "s:COMPRESS_COMMAND=.*$:COMPRESS_COMMAND=${EPREFIX}/bin/gzip:" \
|
||||
src/EDITME > Local/Makefile
|
||||
|
||||
if use elibc_musl; then
|
||||
sed -e 's/^LIBS = -lnsl/LIBS =/g' \
|
||||
-i OS/Makefile-Linux
|
||||
fi
|
||||
|
||||
cd Local
|
||||
|
||||
cat >> Makefile <<- EOC
|
||||
INFO_DIRECTORY=${EPREFIX}/usr/share/info
|
||||
PID_FILE_PATH=${EPREFIX}/run/exim.pid
|
||||
SPOOL_DIRECTORY=${EPREFIX}/var/spool/exim
|
||||
HAVE_ICONV=yes
|
||||
EOC
|
||||
|
||||
# if we use libiconv, now is the time to tell so
|
||||
use !elibc_glibc && use !elibc_musl && echo "EXTRALIBS_EXIM=-liconv" >> Makefile
|
||||
|
||||
# support for IPv6
|
||||
if use ipv6; then
|
||||
cat >> Makefile <<- EOC
|
||||
HAVE_IPV6=YES
|
||||
EOC
|
||||
fi
|
||||
|
||||
#
|
||||
# mail storage formats
|
||||
|
||||
# mailstore is Exim's traditional storage format
|
||||
cat >> Makefile <<- EOC
|
||||
SUPPORT_MAILSTORE=yes
|
||||
EOC
|
||||
|
||||
# mbox
|
||||
if use mbx; then
|
||||
cat >> Makefile <<- EOC
|
||||
SUPPORT_MBX=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
# maildir
|
||||
if use maildir; then
|
||||
cat >> Makefile <<- EOC
|
||||
SUPPORT_MAILDIR=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
#
|
||||
# lookup methods
|
||||
|
||||
# use the "native" interfaces to the DBM and CDB libraries, support
|
||||
# passwd and directory lookups by default
|
||||
cat >> Makefile <<- EOC
|
||||
USE_DB=yes
|
||||
DBMLIB=-ldb
|
||||
LOOKUP_CDB=yes
|
||||
LOOKUP_PASSWD=yes
|
||||
LOOKUP_DSEARCH=yes
|
||||
EOC
|
||||
|
||||
if ! use dnsdb; then
|
||||
# DNSDB lookup is enabled by default
|
||||
sed -i "s:^LOOKUP_DNSDB=yes:# LOOKUP_DNSDB=yes:" Makefile
|
||||
fi
|
||||
|
||||
if use ldap; then
|
||||
cat >> Makefile <<- EOC
|
||||
LOOKUP_LDAP=yes
|
||||
LDAP_LIB_TYPE=OPENLDAP2
|
||||
LOOKUP_INCLUDE += -I"${EROOT}"usr/include/ldap
|
||||
LOOKUP_LIBS += -lldap -llber
|
||||
EOC
|
||||
fi
|
||||
|
||||
if use mysql; then
|
||||
cat >> Makefile <<- EOC
|
||||
LOOKUP_MYSQL=yes
|
||||
LOOKUP_INCLUDE += $(mysql_config --include)
|
||||
LOOKUP_LIBS += $(mysql_config --libs)
|
||||
EOC
|
||||
fi
|
||||
|
||||
if use nis; then
|
||||
cat >> Makefile <<- EOC
|
||||
LOOKUP_NIS=yes
|
||||
LOOKUP_NISPLUS=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
if use postgres; then
|
||||
cat >> Makefile <<- EOC
|
||||
LOOKUP_PGSQL=yes
|
||||
LOOKUP_INCLUDE += -I$(pg_config --includedir)
|
||||
LOOKUP_LIBS += -L$(pg_config --libdir) -lpq
|
||||
EOC
|
||||
fi
|
||||
|
||||
if use sqlite; then
|
||||
cat >> Makefile <<- EOC
|
||||
LOOKUP_SQLITE=yes
|
||||
LOOKUP_SQLITE_PC=sqlite3
|
||||
EOC
|
||||
fi
|
||||
|
||||
if use redis; then
|
||||
cat >> Makefile <<- EOC
|
||||
LOOKUP_REDIS=yes
|
||||
LOOKUP_LIBS += -lhiredis
|
||||
EOC
|
||||
fi
|
||||
|
||||
#
|
||||
# Exim monitor, enabled by default, controlled via X USE-flag,
|
||||
# disable if not requested, bug #46778
|
||||
if use X; then
|
||||
cp ../exim_monitor/EDITME eximon.conf || die
|
||||
else
|
||||
sed -i -e '/^EXIM_MONITOR=/s/^/# /' Makefile
|
||||
fi
|
||||
|
||||
#
|
||||
# features
|
||||
|
||||
# content scanning support
|
||||
if use exiscan-acl; then
|
||||
cat >> Makefile <<- EOC
|
||||
WITH_CONTENT_SCAN=yes
|
||||
WITH_OLD_DEMIME=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
# DomainKeys Identified Mail, RFC4871
|
||||
if ! use dkim; then
|
||||
# DKIM is enabled by default
|
||||
cat >> Makefile <<- EOC
|
||||
DISABLE_DKIM=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Per-Recipient-Data-Response
|
||||
if ! use prdr; then
|
||||
# PRDR is enabled by default
|
||||
cat >> Makefile <<- EOC
|
||||
DISABLE_PRDR=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
# log to syslog
|
||||
if use syslog; then
|
||||
sed -i "s:LOG_FILE_PATH=/var/log/exim/exim_%s.log:LOG_FILE_PATH=syslog:" Makefile
|
||||
cat >> Makefile <<- EOC
|
||||
LOG_FILE_PATH=syslog
|
||||
EOC
|
||||
else
|
||||
cat >> Makefile <<- EOC
|
||||
LOG_FILE_PATH=${EPREFIX}/var/log/exim/exim_%s.log
|
||||
EOC
|
||||
fi
|
||||
|
||||
# starttls support (ssl)
|
||||
if use ssl; then
|
||||
echo "SUPPORT_TLS=yes" >> Makefile
|
||||
if use gnutls; then
|
||||
echo "USE_GNUTLS=yes" >> Makefile
|
||||
echo "USE_GNUTLS_PC=gnutls" >> Makefile
|
||||
use pkcs11 || echo "AVOID_GNUTLS_PKCS11=yes" >> Makefile
|
||||
else
|
||||
echo "USE_OPENSSL_PC=openssl" >> Makefile
|
||||
fi
|
||||
fi
|
||||
|
||||
# TCP wrappers
|
||||
if use tcpd; then
|
||||
cat >> Makefile <<- EOC
|
||||
USE_TCP_WRAPPERS=yes
|
||||
EXTRALIBS_EXIM += -lwrap
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Light Mail Transport Protocol
|
||||
if use lmtp; then
|
||||
cat >> Makefile <<- EOC
|
||||
TRANSPORT_LMTP=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
# embedded Perl
|
||||
if use perl; then
|
||||
cat >> Makefile <<- EOC
|
||||
EXIM_PERL=perl.o
|
||||
EOC
|
||||
fi
|
||||
|
||||
# dlfunc
|
||||
if use dlfunc; then
|
||||
cat >> Makefile <<- EOC
|
||||
EXPAND_DLFUNC=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Proxy Protocol
|
||||
if use proxy; then
|
||||
cat >> Makefile <<- EOC
|
||||
SUPPORT_PROXY=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
#
|
||||
# experimental features
|
||||
|
||||
# DANE
|
||||
if use dane; then
|
||||
cat >> Makefile <<- EOC
|
||||
EXPERIMENTAL_DANE=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Distributed Checksum Clearinghouse
|
||||
if use dcc; then
|
||||
echo "EXPERIMENTAL_DCC=yes">> Makefile
|
||||
fi
|
||||
|
||||
# Sender Policy Framework
|
||||
if use spf; then
|
||||
cat >> Makefile <<- EOC
|
||||
EXPERIMENTAL_SPF=yes
|
||||
EXTRALIBS_EXIM += -lspf2
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Sender Rewriting Scheme
|
||||
if use srs; then
|
||||
cat >> Makefile <<- EOC
|
||||
EXPERIMENTAL_SRS=yes
|
||||
EXTRALIBS_EXIM += -lsrs_alt
|
||||
EOC
|
||||
fi
|
||||
|
||||
# DMARC
|
||||
if use dmarc; then
|
||||
cat >> Makefile <<- EOC
|
||||
EXPERIMENTAL_DMARC=yes
|
||||
EXTRALIBS_EXIM += -lopendmarc
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Transport post-delivery actions
|
||||
if use tpda; then
|
||||
cat >> Makefile <<- EOC
|
||||
EXPERIMENTAL_EVENT=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Delivery Sender Notifications
|
||||
if use dsn; then
|
||||
cat >> Makefile <<- EOC
|
||||
EXPERIMENTAL_DSN=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
#
|
||||
# authentication (SMTP AUTH)
|
||||
|
||||
# standard bits
|
||||
cat >> Makefile <<- EOC
|
||||
AUTH_SPA=yes
|
||||
AUTH_CRAM_MD5=yes
|
||||
AUTH_PLAINTEXT=yes
|
||||
EOC
|
||||
|
||||
# Cyrus SASL
|
||||
if use sasl; then
|
||||
cat >> Makefile <<- EOC
|
||||
CYRUS_SASLAUTHD_SOCKET=${EPREFIX}/run/saslauthd/mux
|
||||
AUTH_CYRUS_SASL=yes
|
||||
AUTH_LIBS += -lsasl2
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Dovecot
|
||||
if use dovecot-sasl; then
|
||||
cat >> Makefile <<- EOC
|
||||
AUTH_DOVECOT=yes
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Pluggable Authentication Modules
|
||||
if use pam; then
|
||||
cat >> Makefile <<- EOC
|
||||
SUPPORT_PAM=yes
|
||||
AUTH_LIBS += -lpam
|
||||
EOC
|
||||
fi
|
||||
|
||||
# Radius
|
||||
if use radius; then
|
||||
cat >> Makefile <<- EOC
|
||||
RADIUS_CONFIG_FILE=${EPREFIX}/etc/radiusclient/radiusclient.conf
|
||||
RADIUS_LIB_TYPE=RADIUSCLIENTNEW
|
||||
AUTH_LIBS += -lfreeradius-client
|
||||
EOC
|
||||
fi
|
||||
}
|
||||
|
||||
src_compile() {
|
||||
emake CC="$(tc-getCC)" HOSTCC="$(tc-getCC $CBUILD)" \
|
||||
AR="$(tc-getAR) cq" RANLIB="$(tc-getRANLIB)" FULLECHO='' \
|
||||
|| die "make failed"
|
||||
}
|
||||
|
||||
src_install () {
|
||||
cd "${S}"/build-exim-gentoo || die
|
||||
dosbin exim
|
||||
if use X; then
|
||||
dosbin eximon.bin
|
||||
dosbin eximon
|
||||
fi
|
||||
fperms 4755 /usr/sbin/exim
|
||||
|
||||
dosym exim /usr/sbin/sendmail
|
||||
dosym exim /usr/sbin/rsmtp
|
||||
dosym exim /usr/sbin/rmail
|
||||
dosym ../sbin/exim /usr/bin/mailq
|
||||
dosym ../sbin/exim /usr/bin/newaliases
|
||||
dosym ../sbin/sendmail /usr/lib/sendmail
|
||||
|
||||
for i in exicyclog exim_dbmbuild exim_dumpdb exim_fixdb exim_lock \
|
||||
exim_tidydb exinext exiwhat exigrep eximstats exiqsumm exiqgrep \
|
||||
convert4r3 convert4r4 exipick
|
||||
do
|
||||
dosbin $i
|
||||
done
|
||||
|
||||
dodoc "${S}"/doc/*
|
||||
doman "${S}"/doc/exim.8
|
||||
use dsn && dodoc "${S}"/README.DSN
|
||||
use doc && dodoc "${WORKDIR}"/${PN}-pdf-${PV//rc/RC}/doc/*.pdf
|
||||
|
||||
# conf files
|
||||
insinto /etc/exim
|
||||
newins "${S}"/src/configure.default exim.conf.dist
|
||||
if use exiscan-acl; then
|
||||
newins "${S}"/src/configure.default exim.conf.exiscan-acl
|
||||
fi
|
||||
doins "${WORKDIR}"/system_filter.exim
|
||||
doins "${FILESDIR}"/auth_conf.sub
|
||||
|
||||
pamd_mimic system-auth exim auth account
|
||||
|
||||
# headers, #436406
|
||||
if use dlfunc ; then
|
||||
# fixup includes so they actually can be found when including
|
||||
sed -i \
|
||||
-e '/#include "\(config\|store\|mytypes\).h"/s:"\(.\+\)":<exim/\1>:' \
|
||||
local_scan.h || die
|
||||
insinto /usr/include/exim
|
||||
doins {config,local_scan}.h ../src/{mytypes,store}.h
|
||||
fi
|
||||
|
||||
insinto /etc/logrotate.d
|
||||
newins "${FILESDIR}/exim.logrotate" exim
|
||||
|
||||
newinitd "${FILESDIR}"/exim.rc10 exim
|
||||
newconfd "${FILESDIR}"/exim.confd exim
|
||||
|
||||
systemd_dounit "${FILESDIR}"/{exim.service,exim.socket,exim-submission.socket}
|
||||
systemd_newunit "${FILESDIR}"/exim_at.service 'exim@.service'
|
||||
systemd_newunit "${FILESDIR}"/exim-submission_at.service 'exim-submission@.service'
|
||||
|
||||
diropts -m 0750 -o ${MAILUSER} -g ${MAILGROUP}
|
||||
dodir /var/log/${PN}
|
||||
}
|
||||
|
||||
pkg_postinst() {
|
||||
if [[ ! -f ${EROOT}etc/exim/exim.conf ]] ; then
|
||||
einfo "${EROOT}etc/exim/system_filter.exim is a sample system_filter."
|
||||
einfo "${EROOT}etc/exim/auth_conf.sub contains the configuration sub for using smtp auth."
|
||||
einfo "Please create ${EROOT}etc/exim/exim.conf from ${EROOT}etc/exim/exim.conf.dist."
|
||||
fi
|
||||
use dane && einfo "DANE support is experimental"
|
||||
if use dcc ; then
|
||||
einfo "DCC support is experimental, you can find some limited"
|
||||
einfo "documentation at the bottom of this prerelease message:"
|
||||
einfo "http://article.gmane.org/gmane.mail.exim.devel/3579"
|
||||
fi
|
||||
use spf && einfo "SPF support is experimental"
|
||||
use srs && einfo "SRS support is experimental"
|
||||
if use dmarc ; then
|
||||
einfo "DMARC support is experimental. See global settings to"
|
||||
einfo "configure DMARC, for usage see the documentation at "
|
||||
einfo "experimental-spec.txt."
|
||||
fi
|
||||
use tpda && einfo "TPDA/EVENT support is experimental"
|
||||
use dsn && einfo "DSN support is experimental"
|
||||
elog "The obsolete acl condition 'demime' is removed, the replacements"
|
||||
elog "are the ACLs acl_smtp_mime and acl_not_smtp_mime"
|
||||
}
|
||||
40
mail-mta/exim/files/exim-4.89-CVE-2017-16943.patch
Normal file
40
mail-mta/exim/files/exim-4.89-CVE-2017-16943.patch
Normal file
@@ -0,0 +1,40 @@
|
||||
From 4e6ae6235c68de243b1c2419027472d7659aa2b4 Mon Sep 17 00:00:00 2001
|
||||
From: Jeremy Harris <jgh146exb@wizmail.org>
|
||||
Date: Fri, 24 Nov 2017 20:22:33 +0000
|
||||
Subject: [PATCH] Avoid release of store if there have been later allocations.
|
||||
Bug 2199
|
||||
|
||||
---
|
||||
src/src/receive.c | 7 ++++---
|
||||
1 file changed, 4 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/src/src/receive.c b/src/src/receive.c
|
||||
index e7e518a..d9b5001 100644
|
||||
--- a/src/src/receive.c
|
||||
+++ b/src/src/receive.c
|
||||
@@ -1810,8 +1810,8 @@ for (;;)
|
||||
(and sometimes lunatic messages can have ones that are 100s of K long) we
|
||||
call store_release() for strings that have been copied - if the string is at
|
||||
the start of a block (and therefore the only thing in it, because we aren't
|
||||
- doing any other gets), the block gets freed. We can only do this because we
|
||||
- know there are no other calls to store_get() going on. */
|
||||
+ doing any other gets), the block gets freed. We can only do this release if
|
||||
+ there were no allocations since the once that we want to free. */
|
||||
|
||||
if (ptr >= header_size - 4)
|
||||
{
|
||||
@@ -1820,9 +1820,10 @@ for (;;)
|
||||
header_size *= 2;
|
||||
if (!store_extend(next->text, oldsize, header_size))
|
||||
{
|
||||
+ BOOL release_ok = store_last_get[store_pool] == next->text;
|
||||
uschar *newtext = store_get(header_size);
|
||||
memcpy(newtext, next->text, ptr);
|
||||
- store_release(next->text);
|
||||
+ if (release_ok) store_release(next->text);
|
||||
next->text = newtext;
|
||||
}
|
||||
}
|
||||
--
|
||||
1.9.1
|
||||
|
||||
Reference in New Issue
Block a user