- Tue Jan 8 2013 Johnny Hughes <johnny@centos.org> - 1.4.8-21.el5.centos
- remove upstream branding
- Tue Jul 3 2012 Michal Hlavinka <mhlavink@redhat.com> - 1.4.8-21
- change charset for zh_CN and zh_TW to utf-8 (#508686)
- Mon Jun 25 2012 Michal Hlavinka <mhlavink@redhat.com> - 1.4.8-20
- fix header encoding issue (#241861)
- fix code producing warnings in the log (#475188) - Wed Jun 20 2012 Michal Hlavinka <mhlavink@redhat.com> - 1.4.8-19
- patch for CVE-2010-2813 modified wrong file (#808598)
- correct requirement is mod_php not php (#789353)
- comply with RFC2822 line length limits (#745469)
- document that SELinux boolean httpd_can_sendmail needs to be
turned on (#745380)
- add support for big UIDs on 32bit machines (#450780)
- do not corrupt html attachments (#359791) - Tue Jan 31 2012 Michal Hlavinka <mhlavink@redhat.com> - 1.4.8-18
- fix typo in CVE-2010-4555 patch
- Wed Oct 12 2011 Michal Hlavinka <mhlavink@redhat.com> - 1.4.8-17
- patch for CVE-2010-2813 was not complete
- Wed Sep 14 2011 Michal Hlavinka <mhlavink@redhat.com> - 1.4.8-16
- fix: CVE-2010-1637 : Port-scans via non-standard POP3 server ports in
Mail Fetch plugin
- fix: CVE-2010-2813 : DoS (disk space consumption) by random IMAP login
attempts with 8-bit characters in the password
- fix: CVE-2010-4554 : Prone to clickjacking attacks
- fix: CVE-2010-4555 : Multiple XSS flaws
- fix: CVE-2011-2023 : XSS in