-----BEGIN PGP SIGNED MESSAGE----- Format: 1.7 Date: Tue, 29 May 2007 02:21:00 -0000 Source: sendmail Binary: libmilter-dev libmilter1-dbg rmail libmilter1 sendmail sendmail-doc sendmail-cf sensible-mda sendmail-base sendmail-bin Architecture: source all amd64 Version: 8.14.1-6 Distribution: unstable Urgency: low Maintainer: Richard A Nelson (Rick) <cowboy@debian.org> Changed-By: Richard A Nelson (Rick) <cowboy@debian.org> Description: libmilter-dev - Sendmail Mail Filter API (Milter) libmilter1 - Sendmail Mail Filter API (Milter) libmilter1-dbg - Sendmail Mail Filter API (Milter) rmail - MTA->UUCP remote mail handler sendmail - powerful, efficient, and scalable Mail Transport Agent sendmail-base - powerful, efficient, and scalable Mail Transport Agent sendmail-bin - powerful, efficient, and scalable Mail Transport Agent sendmail-cf - powerful, efficient, and scalable Mail Transport Agent sendmail-doc - powerful, efficient, and scalable Mail Transport Agent sensible-mda - Mail Delivery Agent wrapper Changes: sendmail (8.14.1-6) unstable; urgency=low . * The `ironclad or die` release, using newer gcc/binutils features to further reduce the exploit footprint of an application. Thanks to Marc-Christian Petersen Read more about all that good stuff at: http://www.gentoo.org/proj/en/hardened/hardened-toolchain.xml#RELRO . * Create an ELF "PT_GNU_RELRO" segment header in the object. Or in other words: built with "-z relro" . * When generating an executable or shared library, mark it to tell the dynamic linker to resolve all symbols when the program is started, or when the shared library is linked to using dlopen, instead of deferring function call resolution to the point when the function is first called. Or in other words: built with "-z now" . * Emit extra code to check for buffer overflows, such as stack smashing attacks. This is done by adding a guard variable to functions with vulnerable objects. This includes functions that call alloca, and functions with buffers larger than 8 bytes. The guards are initialized when a function is entered and then checked when the function exits. If a guard check fails, an error message is printed and the program exits. Or in other words: built with "-fstack-protector-all" . * Compiled as PIE (Position Independant Executable) This assists PAX enabled kernels, with ASLR, and is also needed for GRSecurity. Even with stock kernels, this makes the memory mapping less static, hindering attacks. Files: 3c1c09d47c6e43d9f891d2fb624c9cb2 1100 mail extra sendmail_8.14.1-6.dsc f3104246b7505bf849ec35e4a195adce 353214 mail extra sendmail_8.14.1-6.diff.gz 08d3a90d79d0a6221aac57127545cf7d 829040 doc extra sendmail-doc_8.14.1-6_all.deb d5683b2438492522d1601bb30202d247 201048 mail extra sendmail_8.14.1-6_all.deb b6d876392fd3575031b883a2bcf43a95 349854 mail extra sendmail-base_8.14.1-6_all.deb c98062f7f2b56c1db73a2ab9afa8cb58 289754 mail extra sendmail-cf_8.14.1-6_all.deb 87344f0ac5a8ca97067ddf08d044a66e 949118 mail extra sendmail-bin_8.14.1-6_amd64.deb 795e422e4e32b495c64f923efe1a824c 239186 mail extra rmail_8.14.1-6_amd64.deb 53d3bb70f4e5523b1d3a289624f2c555 209136 mail extra sensible-mda_8.14.1-6_amd64.deb c97c15d454ef4604f246a4c27b95bf48 229426 libs extra libmilter1_8.14.1-6_amd64.deb d1f78674f4b5dfeb730acdd251e055fc 251052 libs extra libmilter1-dbg_8.14.1-6_amd64.deb 35349ba06e4f02612584d63fa35caabc 318124 libdevel extra libmilter-dev_8.14.1-6_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iQCVAwUBRn2yMaVTksHk9ElFAQEbDgP+LcJR/WQ9c1w66oSPigxABUXOkpx9VhVs TpYx1jpI2mtJ4JYVSxaJZspJ19Ks6khhM2KYYsk1azL9PqxDUFwMkpXtN+DMZR3o IaBmjtxBr9/y/7Q/qUqZtkfmjwQccH3yNayADDcH5DZ0f/Cx2N3LPr7Y3zk4BMp2 ErUVhcYvBi8= =sg5z -----END PGP SIGNATURE----- Accepted: libmilter-dev_8.14.1-6_amd64.deb to pool/main/s/sendmail/libmilter-dev_8.14.1-6_amd64.deb libmilter1-dbg_8.14.1-6_amd64.deb to pool/main/s/sendmail/libmilter1-dbg_8.14.1-6_amd64.deb libmilter1_8.14.1-6_amd64.deb to pool/main/s/sendmail/libmilter1_8.14.1-6_amd64.deb rmail_8.14.1-6_amd64.deb to pool/main/s/sendmail/rmail_8.14.1-6_amd64.deb sendmail-base_8.14.1-6_all.deb to pool/main/s/sendmail/sendmail-base_8.14.1-6_all.deb sendmail-bin_8.14.1-6_amd64.deb to pool/main/s/sendmail/sendmail-bin_8.14.1-6_amd64.deb sendmail-cf_8.14.1-6_all.deb to pool/main/s/sendmail/sendmail-cf_8.14.1-6_all.deb sendmail-doc_8.14.1-6_all.deb to pool/main/s/sendmail/sendmail-doc_8.14.1-6_all.deb sendmail_8.14.1-6.diff.gz to pool/main/s/sendmail/sendmail_8.14.1-6.diff.gz sendmail_8.14.1-6.dsc to pool/main/s/sendmail/sendmail_8.14.1-6.dsc sendmail_8.14.1-6_all.deb to pool/main/s/sendmail/sendmail_8.14.1-6_all.deb sensible-mda_8.14.1-6_amd64.deb to pool/main/s/sendmail/sensible-mda_8.14.1-6_amd64.deb