Crash bug discovered

From: Murray S. Kucherawy <msk_at_blackops.org>
Date: Fri, 12 Mar 2010 15:52:49 -0800 (PST)

2.0.0 has a crash bug at signing. dkim_sign() expects a NULL-terminated
string as the private key, and opendkim's not taking steps to ensure
proper termination, eventually causing strlen() to segfault. It just
crashed on blackops.org with that problem.

I've opened a bug on SourceForge containing a patch that fixes it.

I have 2.0.1 slated to go out on Monday the 22nd. I think this warrants
moving it up a week to the 15th, but I'll wait if people think posting a
patch is sufficient.
Received on Fri Mar 12 2010 - 23:53:06 PST

This archive was generated by hypermail 2.3.0 : Mon Oct 29 2012 - 23:32:52 PST