Subject: CVS commit: [pkgsrc-2008Q2] pkgsrc/mail/postfix
From: Tyler R. Retzlaff
Date: 2008-08-18 11:46:08
Message id: 20080818094608.98435175D7@cvs.netbsd.org

Log Message:
pullup ticket #2495 - requested by martti
postfix: update package for security fixes

revisions pulled up:
pkgsrc/mail/postfix/Makefile	1.218
pkgsrc/mail/postfix/distinfo	1.118

   Module Name:    pkgsrc
   Committed By:   martti
   Date:           Mon Aug 18 07:13:41 UTC 2008

   Modified Files:
           pkgsrc/mail/postfix: Makefile distinfo

   Log Message:
   Updated mail/postfix to 2.5.4

   20080804

           Bugfix: dangling pointer in vstring_sprintf_prepend().
           File: util/vstring.c.

   20080814

           Security: some systems have changed their link() semantics,
           and will hardlink a symlink, contrary to POSIX and XPG4.
           Sebastian Krahmer, SuSE. File: util/safe_open.c.

           The solution introduces the following incompatible change:
           when the target of mail delivery is a symlink, the parent
           directory of that symlink must now be writable by root only
           (in addition to the already existing requirement that the
           symlink itself is owned by root).  This change will break
           legitimate configurations that deliver mail to a symbolic
           link in a directory with less restrictive permissions.

Files:
RevisionActionfile
1.216.6.1modifypkgsrc/mail/postfix/Makefile
1.116.6.1modifypkgsrc/mail/postfix/distinfo