Hello community, here is the log from the commit of package msmtp for openSUSE:Factory checked in at 2019-02-26 22:21:43 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/msmtp (Old) and /work/SRC/openSUSE:Factory/.msmtp.new.28833 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "msmtp" Tue Feb 26 22:21:43 2019 rev:43 rq:679267 version:1.8.3 Changes: -------- --- /work/SRC/openSUSE:Factory/msmtp/msmtp.changes 2019-02-15 10:04:21.123587962 +0100 +++ /work/SRC/openSUSE:Factory/.msmtp.new.28833/msmtp.changes 2019-02-26 22:23:07.466050755 +0100 @@ -1,0 +2,10 @@ +Thu Feb 14 20:48:32 UTC 2019 - BenoƮt Monin <benoit.mo...@gmx.fr> + +- update to version 1.8.3 (boo#1125420) + * CVE-2019-8337 + This version fixes a security problem that affects version + 1.8.2 (older versions are not affected): when the new default + value system for tls_trust_file is used, the result of + certificate verification was not properly checked. + +------------------------------------------------------------------- Old: ---- msmtp-1.8.2.tar.xz msmtp-1.8.2.tar.xz.sig New: ---- msmtp-1.8.3.tar.xz msmtp-1.8.3.tar.xz.sig ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ msmtp.spec ++++++ --- /var/tmp/diff_new_pack.bLeZPT/_old 2019-02-26 22:23:07.962050579 +0100 +++ /var/tmp/diff_new_pack.bLeZPT/_new 2019-02-26 22:23:07.966050578 +0100 @@ -17,7 +17,7 @@ Name: msmtp -Version: 1.8.2 +Version: 1.8.3 Release: 0 BuildRequires: gnutls-devel BuildRequires: libidn2-devel ++++++ msmtp-1.8.2.tar.xz -> msmtp-1.8.3.tar.xz ++++++ ++++ 2486 lines of diff (skipped)