[Amavisd-new-debian-devel] RC bug #527862: libmilter1.0.1: segfault in libmilter - using milter-greylist and mimedefang - both dies

Harald Jenny harald at a-little-linux-box.at
Sat Dec 11 11:52:47 UTC 2010


Dear release team and package maintainers,

first my apologies for this mass mailing but as the problem described in the
subject affects a dozen of programs (at least according to their Depends-field)
I thought it would be beneficial to allow everybody to participate in this
"conversation". The issue at hand is that a bug in the current version of
libmilter which is available in Debian Squeeze (8.14.3-9.4) leads to sefaults
of the affected programs when hit my milter requests. Affected packages are:

amavisd-milter
batv-milter
libbobcat2
clamav-milter
dkim-filter
libsendmail-milter-perl
milter-greylist
mimedefang
opendkim
python-milter
spamass-milter
spfmilter

As the combined number of current installations (according to popcon, state
2010-12) is 1085, I would desperately ask the release team and the sendmail
packager Richard A Nelson for a solution to this problem. Debian Sid contains
a 8.14.4-2 version of libmilter which according to my testings fixes the
problem at hand, but also introduces other changes, one of them with a security
background fixing CVE-2009-4565. May I ask for feedback from the release team
and Richard A Nelson concerning this matter?

Kind regards
Harald Jenny



More information about the Amavisd-new-debian-devel mailing list