After 6 years of inactivity, fetchmail 6.4.0 is now available

More than 6 years have passed since the last update has been released a program for the delivery and forwarding of email fetchmail 6.4.0, allowing retrieval of mail using protocols and extensions such as POP2, POP3, RPOP, APOP, KPOP, IMAP, ETRN, and ODMR, filtering incoming correspondence, distributing messages from one account to multiple users, and forwarding to local mailboxes or via SMTP to another server (functioning as a POP/IMAP-to-SMTP gateway). The project code is written in C and is distributed is licensed under GPLv2. Support for the fetchmail 6.3.X branch has been completely discontinued.

Among the changes:

  • Support for TLS 1.1, 1.2, and 1.3 has been added (—sslproto {tls1.1+|tls1.2+|tls1.3+}). Default builds are included with OpenSSL (at least version 1.0.2 is required, and for TLSv1.3 — 1.1.1). Support for SSLv2 has been dropped. By default, TLSv1.1 is now declared instead of SSLv3 and TLSv1.0 in STLS/STARTTLS. To revert to SSLv3, OpenSSL with SSLv3 support must be used, and fetchmail should be run with the flag "—sslproto ssl3+".
  • By default, SSL certificate verification is enabled (—sslcertck). To disable verification, the option "—nosslcertck" must now be explicitly specified;
  • Support for very old C compilers has been dropped. A compiler supporting the 2002 SUSv3 standard (Single Unix Specification v3, a subset of POSIX.1-2001 with XSI extensions) is now required for building;
  • The efficiency of UID tracking (the "—keep UID" mode) has been increased when distributing messages from a mailbox via POP3;
  • Numerous improvements related to support for encrypted connections have been made;
  • A vulnerability that could lead to a buffer overflow in authentication code via GSSAPI when handling usernames longer than 6000 characters has been eliminated.

The vulnerability is confirmed in many official Docker images, including images for Couchbase, Elasticsearch, Flink, Solr, Storm, etc. is available release 6.4.1 with fixes for two regressions (incomplete fixes to Debian bug 941129 caused issues in locating fetchmail configuration files in some cases and a problem with _FORTIFY_SOURCE when PATH_MAX exceeds the minimum _POSIX_PATH_MAX).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster