Bug 231412 - mail/spamassassin 3.4.2 upgrade required - CVEs and performance enhancements
Summary: mail/spamassassin 3.4.2 upgrade required - CVEs and performance enhancements
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: Niclas Zeising
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-09-16 22:57 UTC by dewayne
Modified: 2018-09-28 19:14 UTC (History)
1 user (show)

See Also:
bugzilla: maintainer-feedback? (zeising)


Attachments
patch-to-3.4.2 (24.32 KB, patch)
2018-09-20 18:01 UTC, Kurt Jaeger
no flags Details | Diff
Update spamassassin to 3.4.2 (26.09 KB, patch)
2018-09-21 13:14 UTC, Niclas Zeising
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description dewayne 2018-09-16 22:57:23 UTC
So that the CVE's notified by Apache Software Foundation, on their mailing list is actioned/tracked.  For details please review

https://lists.apache.org/thread.html/1ac11532235b5459aa16c4e9d636bf4aa0b141d347d1361e40cc1b78@%3Cannounce.apache.org%3E

There are some performance and security enhancements also included with 3.1.2 apart from addressing issues that are reported "in the wild".
Comment 1 Niclas Zeising freebsd_committer 2018-09-17 10:26:17 UTC
Hi!
I am aware of the issue, I'll update the port as soon as I can.
Comment 2 Kurt Jaeger freebsd_committer 2018-09-20 18:01:37 UTC
Created attachment 197286 [details]
patch-to-3.4.2

Can you comment on this patch ? Testbuilds are fine.
Comment 3 Niclas Zeising freebsd_committer 2018-09-21 13:14:18 UTC
Created attachment 197301 [details]
Update spamassassin to 3.4.2

Hi!
Here is a patch that I've circulated for testing.  Please test it.
Be sure to take a backup of spamassassin data before, such as things learned by sa-learn.
Thanks!
Regards
-- 
Niclas
Comment 4 commit-hook freebsd_committer 2018-09-26 19:30:49 UTC
A commit references this bug:

Author: zeising
Date: Wed Sep 26 19:30:37 UTC 2018
New revision: 480763
URL: https://svnweb.freebsd.org/changeset/ports/480763

Log:
  mail/spamassassin: Update to 3.4.2

  Update mail/spamassassin to 3.4.2.  This update includes security fixes.
  For complete changelog and upgrade notes, see:
  https://mail-archives.apache.org/mod_mbox/spamassassin-announce/201809.mbox/%3cc44ca0f1-cba9-b129-20b2-ba59816cfd13@apache.org%3e

  Big thanks to Larry Rosenman (ler) for help with testing!

  PR:		231412
  Reported by:	dewayne@heuristicsystems.com.au
  Tested by:	ler
  MFH:		2018Q3
  Security:	613193a0-c1b4-11e8-ae2d-54e1ad3d6335

Changes:
  head/mail/spamassassin/Makefile
  head/mail/spamassassin/distinfo
  head/mail/spamassassin/files/patch-DnsResolver.pm
  head/mail/spamassassin/files/patch-bug7199
  head/mail/spamassassin/files/patch-bug7208
  head/mail/spamassassin/files/patch-bug7231
  head/mail/spamassassin/files/patch-bug7265
  head/mail/spamassassin/files/patch-bug7404
  head/mail/spamassassin/files/sa-spamd.in
  head/mail/spamassassin/pkg-plist
Comment 5 Niclas Zeising freebsd_committer 2018-09-26 19:44:26 UTC
Spamassassin has been updated.
Comment 6 commit-hook freebsd_committer 2018-09-28 19:14:01 UTC
A commit references this bug:

Author: zeising
Date: Fri Sep 28 19:13:05 UTC 2018
New revision: 480880
URL: https://svnweb.freebsd.org/changeset/ports/480880

Log:
  MFH: r480763

  mail/spamassassin: Update to 3.4.2

  Update mail/spamassassin to 3.4.2.  This update includes security fixes.
  For complete changelog and upgrade notes, see:
  https://mail-archives.apache.org/mod_mbox/spamassassin-announce/201809.mbox/%3cc44ca0f1-cba9-b129-20b2-ba59816cfd13@apache.org%3e

  Big thanks to Larry Rosenman (ler) for help with testing!

  PR:		231412
  Reported by:	dewayne@heuristicsystems.com.au
  Tested by:	ler
  Security:	613193a0-c1b4-11e8-ae2d-54e1ad3d6335

  Approved by:	ports-secteam (miwi)

Changes:
_U  branches/2018Q3/
  branches/2018Q3/mail/spamassassin/Makefile
  branches/2018Q3/mail/spamassassin/distinfo
  branches/2018Q3/mail/spamassassin/files/patch-DnsResolver.pm
  branches/2018Q3/mail/spamassassin/files/patch-bug7199
  branches/2018Q3/mail/spamassassin/files/patch-bug7208
  branches/2018Q3/mail/spamassassin/files/patch-bug7231
  branches/2018Q3/mail/spamassassin/files/patch-bug7265
  branches/2018Q3/mail/spamassassin/files/patch-bug7404
  branches/2018Q3/mail/spamassassin/files/sa-spamd.in
  branches/2018Q3/mail/spamassassin/pkg-plist