The 5.9.10 release of fetchmail is now available at the usual locations,
including <URL:http://www.tuxedo.org/~esr/fetchmail>.
The source archive is available at:
<URL:http://www.tuxedo.org/~esr/fetchmail/fetchmail-5.9.10.tar.gz>
Here are the release notes:
fetchmail-5.9.10 (Sun Mar 10 15:09:57 EST 2002), 21529 lines:
* Security fix: don't trust the message count passed back by the server.
fetchmail-5.9.9 (Sat Mar 9 08:54:28 EST 2002), 21508 lines:
* Renamed misnamed tr.po and da.po files
* Jakub Ulanowski's patch to fix SSL fingerprint handling.
* Matt Kraai's patch for supporting STLS over POP3.
* French translation updated.
* Debian fixes merged.
* Added maildrop (MDA shipped with courier) as fallback after procmail
and sendmail (thanks to Alexander Lazic <al-fetchmail(_at_)none(_dot_)at>).
* ESMTP AUTH support from Wojciech Polak <polak(_at_)lodz(_dot_)pdi(_dot_)net>.
There are 481 people on fetchmail-friends and 646 on fetchmail-announce.
Two releases in quick succession, because of the security issue. There was
a theoretically exploitable hole that would have required a hostile server
or DNS spoofing attack.
By popular demand, diffs from the previous release have been omitted.
--
<a href="http://www.tuxedo.org/~esr/">Eric S. Raymond</a>
"Are we to understand," asked the judge, "that you hold your own interests
above the interests of the public?"
"I hold that such a question can never arise except in a society of cannibals."
-- Ayn Rand