Re: [ANNOUNCE] Apache SpamAssassin 3.4.2 available

2018-09-16 Thread Reio Remma
On 17.09.2018 4:13, Ricky Gutierrez wrote: Reio hi, Could you please share the rpm o src for centOS? Download link @WeTransfer: https://we.tl/t-CbvKhwJoCA spamassassin-3.4.2-0.el7.x86_64.rpm Will be deleted on 24 September, 2018. Good luck, Reio

Re: [SECURITY] Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781

2018-09-16 Thread Kevin A. McGrail
Reindl, I question whether I should bother rewarding your bad behavior and again ask.you if you find your negative attitude gets you where you want to be in life? But for others, here are the facts and the policy. "we see that you mentioned these CVE names public at

Re: [SECURITY] Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781

2018-09-16 Thread Kenneth Porter
On 9/16/2018 5:44 PM, Kevin A. McGrail wrote: Thanks for the post.  The bug is way out of line though. Earlier bug that should probably be the one tracked: https://bugzilla.redhat.com/show_bug.cgi?id=1629474

Re: [ANNOUNCE] Apache SpamAssassin 3.4.2 available

2018-09-16 Thread Ricky Gutierrez
Reio hi, Could you please share the rpm o src for centOS? El El dom, sep. 16, 2018 a las 2:10 p. m., Reio Remma escribió: > > > Wonderful, thank you all for your hard work! > > I encountered no problems at all when building a new RPM for CentOS 7. > > Thanks and good luck, > Reio > -- rickygm

Re: [ANNOUNCE] Apache SpamAssassin 3.4.2 available

2018-09-16 Thread Chris
On Sun, 2018-09-16 at 20:54 -0400, Kevin A. McGrail wrote: > Please point them here if they need help. It is a good drop in > upgrade. I would assume it being a security update they'd be on the ball. I'll wait a few days before I ask about it. I could install via cpan but would rather wait on

Re: [ANNOUNCE] Apache SpamAssassin 3.4.2 available

2018-09-16 Thread Kevin A. McGrail
Please point them here if they need help. It is a good drop in upgrade. On Sun, Sep 16, 2018, 20:45 Chris wrote: > On Sun, 2018-09-16 at 11:03 -0400, Kevin A. McGrail wrote: > > Good Morning, > > > > On behalf of the Apache SpamAssassin Project Management Committee, I > > am > > very pleased to

Re: [ANNOUNCE] Apache SpamAssassin 3.4.2 available

2018-09-16 Thread Chris
On Sun, 2018-09-16 at 11:03 -0400, Kevin A. McGrail wrote: > Good Morning, > > On behalf of the Apache SpamAssassin Project Management Committee, I > am > very pleased to announce the release of Apache SpamAssassin v3.4.2. > This release contains security bug fixes. A security announcement >

Re: [SECURITY] Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781

2018-09-16 Thread Kevin A. McGrail
Thanks for the post. The bug is way out of line though. We posted release candidate 1 on the 12th noting the 4 CVE issues coming. I also backchanneled with RH as a heads up. We do have a brain... I have 3.4.2 installed on centos 7 and it was drop-in other than the redhat specific paths,

Re: [SECURITY] Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781

2018-09-16 Thread Kenneth Porter
Here's the Red Hat Bugzilla bug requesting a new package for Fedora/RHEL be issued ASAP: https://bugzilla.redhat.com/show_bug.cgi?id=1629491 Once the official package drops, you should be able to download the SRPM here:

Re: [ANNOUNCE] Apache SpamAssassin 3.4.2 available

2018-09-16 Thread Ricky Gutierrez
Thank you for gr8 software. El El dom, sep. 16, 2018 a las 9:03 a. m., Kevin A. McGrail < kmcgr...@apache.org> escribió: > Good Morning, > > On behalf of the Apache SpamAssassin Project Management Committee, I am > very pleased to announce the release of Apache SpamAssassin v3.4.2. > This

Re: [SECURITY] Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781

2018-09-16 Thread Kevin A. McGrail
Per the asf security team, mitre considers the public rc1 from a few days ago as the start of the clock for the publishing so we were already way past the 24 hour windiw. Hopefully, the announcements and reports are obfuscated and bugzilla ia private so it'll be contained. On Sun, Sep 16, 2018,

Re: [ANNOUNCE] Apache SpamAssassin 3.4.2 available

2018-09-16 Thread Reio Remma
On 16.09.2018 18:03, Kevin A. McGrail wrote: Good Morning, On behalf of the Apache SpamAssassin Project Management Committee, I am very pleased to announce the release of Apache SpamAssassin v3.4.2. This release contains security bug fixes.  A security announcement will follow within the next

[SECURITY] Apache SpamAssassin 3.4.2 resolves CVE-2017-15705, CVE-2016-1238, CVE-2018-11780 & CVE-2018-11781

2018-09-16 Thread Kevin A. McGrail
Apache SpamAssassin 3.4.2 was recently released [1], and fixes several issues of security note. First, a denial of service vulnerability that exists in all modern versions. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan

[ANNOUNCE] Apache SpamAssassin 3.4.2 available

2018-09-16 Thread Kevin A. McGrail
Good Morning, On behalf of the Apache SpamAssassin Project Management Committee, I am very pleased to announce the release of Apache SpamAssassin v3.4.2.  This release contains security bug fixes.  A security announcement will follow within the next 24 hours. Apache SpamAssassin can be