From c205d9413618883356245668bfdc0b7fbc83c5f7 Mon Sep 17 00:00:00 2001 From: Marcus Bointon Date: Fri, 11 Aug 2017 14:48:43 +0200 Subject: [PATCH] Changelog --- changelog.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/changelog.md b/changelog.md index 0bec65fe..44f0125b 100644 --- a/changelog.md +++ b/changelog.md @@ -50,6 +50,8 @@ This is a major update that breaks backwards compatibility. * More reliable folding of message headers * Inject your own SMTP implementation via `setSMTPInstance()` instead of having to subclass and override `getSMTPInstance()`. +* Make obtaining SMTP transaction ID more reliable + ## Version 5.2.24 (July 26th 2017) * **SECURITY** Fix XSS vulnerability in one of the code examples, [CVE-2017-11503](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-11503). The `code_generator.phps` example did not filter user input prior to output. This file is distributed with a `.phps` extension, so it it not normally executable unless it is explicitly renamed, so it is safe by default. There was also an undisclosed potential XSS vulnerability in the default exception handler (unused by default). Patches for both issues kindly provided by Patrick Monnerat of the Fedora Project. * Handle bare codes (an RFC contravention) in SMTP server responses