Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 21 Apr 2016 20:30:00 +0300
From: Solar Designer <>
Subject: list mail bounces; libtiff


About 10 of you have e-mailed the list admins about "ezmlm warning"
messages that some of you received today, so I'll reply to all in here
(expecting that more of you are wondering, but haven't e-mailed us).

Yes, there was a mail delivery problem from oss-security on April 8,
resolved on April 9.

Several of the messages were initially queued up, and when the problem
was resolved and they were finally attempted to be delivered, they could
not be delivered to some of you, as well as to some of the third-party
archives, presumably because of those servers' use of greylisting (or
any other intermittent errors).  Crucially, there was not a second
delivery attempt because of those messages' age in the queue.  Indeed,
this is incompatible with greylisting, and in hindsight we should have
temporarily increased the allowable queue age before resolving the
initial problem.

The official archive has the full set of messages posted on April 8:

Specifically, the multiple notifications about different libtiff
vulnerabilities were affected, so if libtiff is relevant to you please
review the above archive page.


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.