Subject: CVS commit: pkgsrc
To: None <source-changes@netbsd.org>
From: Hubert Feyrer <hubertf@netbsd.org>
List: source-changes
Date: 03/01/2000 16:23:16
Module Name:	pkgsrc
Committed By:	hubertf
Date:		Thu Mar  2 00:23:16 UTC 2000

Modified Files:
	pkgsrc/mail/nmh: Makefile
	pkgsrc/mail/nmh/files: patch-sum
	pkgsrc/mail/nmh/patches: patch-ca patch-cb patch-cc
	pkgsrc/mail/nmh/pkg: PLIST
Removed Files:
	pkgsrc/mail/nmh/patches: patch-cd patch-ce patch-cf patch-cg patch-ch

Log Message:
Update to V1.0.3, per request of our security officers:

Versions prior to 1.0.3 of the nmh package contained a vulnerability
where incoming mail messages with carefully designed MIME headers could
cause nmh's mhshow command to execute arbitrary shell code.

See the changelog for another 372 lines of changes.


To generate a diff of this commit:
cvs rdiff -r1.32 -r1.33 pkgsrc/mail/nmh/Makefile
cvs rdiff -r1.2 -r1.3 pkgsrc/mail/nmh/files/patch-sum
cvs rdiff -r1.2 -r1.3 pkgsrc/mail/nmh/patches/patch-ca
cvs rdiff -r1.4 -r1.5 pkgsrc/mail/nmh/patches/patch-cb
cvs rdiff -r1.1 -r1.2 pkgsrc/mail/nmh/patches/patch-cc
cvs rdiff -r1.1 -r0 pkgsrc/mail/nmh/patches/patch-cd \
    pkgsrc/mail/nmh/patches/patch-ce pkgsrc/mail/nmh/patches/patch-cf \
    pkgsrc/mail/nmh/patches/patch-cg pkgsrc/mail/nmh/patches/patch-ch
cvs rdiff -r1.11 -r1.12 pkgsrc/mail/nmh/pkg/PLIST

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.