MailEnable Professional Release Notes ===================================== 8.68 20th February 2023 ----------------------- FIX: ClamAV 0.103.8 critical patch for CVE-2023-20032/CVE-2023-20052 ADD: New PowerShell commands Get-MailEnableAccess, Set-MailEnableAccess, Add-MailEnableAccess, Remove-MailEnableAccess to manage relay and connection rights ADD: Mailbox ReplyAddress, DefaultAddress, mailboxSMTP-Inbound-Message-UsageRestrictionEnabled and mailboxSMTP-Inbound-Message-UsageRestriction added to PowerShell ADD: Custom options for mailboxes added to PowerShell ADD: Mailbox list in admin shows the inbox message count when using precalculated display FIX: Showing attachments in new window in webmail may open window for another message FIX: SMTP send limits is logging 0 as the amount the mailbox can send per hour FIX: SMTP not closing inbound connection when using STARTTLS FIX: Forwarding messages which are DKIM signed won't add footers to avoid breaking DKIM FIX: Various minor admin changes FIX: Minor webmail changes FIX: Migration service or text indexing could fail when moving to next item in queue FIX: EWS migration could fail if MailEnable.Protocols.EWS.dll file not in path FIX: Webmail not using reply-to header when replying to all FIX: Webmail was allowing users to set same password when forced to change 8.67 9th November 2022 ---------------------- FIX: Important webmail vulnerability from authenticated users FIX: Autoresponder end date in webmail was not saving FIX: Webmail speed inprovements in listing messages 8.66 7th October 2022 --------------------- FIX: Critical webmail vulnerability from authenticated users (thanks to GeorgeT, JohnM and JohnB for the report) FIX: Critical webmail vulnerability from authenticated users (thanks to GeorgeT for the report) FIX: All product fixes since version 8.65 (see https://www.mailenable.com/Professional-ReleaseNotes.txt for details) 8.65 10th October 2019 ---------------------- IMP: Webmail free/busy scheduler in web mail now always lists the organizer of a meeting IMP: WebMail New Mail Notifications now includes the message sender IMP: MEActivityMonitor has been ported to .NET framework FIX: Critical Security Updates FIX: Browser resize issue when listing MyFiles folders when attaching to storage FIX: You can now select a custom calendar when creating an appointment from the main menu FIX: Send button would not render label correctly when composing in new window via Microsoft Edge FIX: Could not publishing a folder in Webmail MyFiles FIX: An error would occur if you create identity in webmail and Reply To address is empty FIX: Webmail tasks are not being filtered for Active or Overdue Tasks FIX: Javascript error would occur when creating a new appointment in webmail and clicking Show Freebusy (work hours) FIX: When editing an appointment in a new window in webmail, freebusy popup was too wide FIX: Webmail is not validating email addresses containing angle brackets when composing FIX: ASP.NET error when updating an appointment and selecting option to send to an attendee FIX: Custom calendar folder did not load the correct view when accessed as a share 8.64 20th June 2019 ------------------- FIX: Platform bug fixes and critical security updates - Thanks to Soroush Dalili of NCC Group ADD: Added login screen option to remove the use of the high resolution background IMP: Webmail search results are now sortable by column IMP: Added additional http request parameter parsing/protection to detect malicious arguments IMP: Webmail search results columns are now resizable IMP: Reduced memory footprint for caching postoffice/organisation directories IMP: Minor webmail stylesheet alignment fixes FIX: Improved the audit logging of failed SMTP authentication attempts to direct to the target user/postoffice rather than assuming the default postoffice FIX: IMAP may show appointment subject as Private for Outlook connector FIX: List server may still generate NDRs for password protects and disabled lists when NDRs were disabled FIX: Base64 encoded UTF-8 subjects that were split may show incorrectly in webmail FIX: Some inline attachments were not shows as attachments in webmail 8.63 28th May 2019 ------------------ FIX: Platform bug fixes and critical security updates - Thanks to Soroush Dalili of NCC Group INF: Rollup patch with fixes applied to version 10.24 See release notes for version 10.24 for more information 8.62 4th July 2018 ------------------ FIX: Installer will correctly install webmail on Windows 2016 FIX: All core services updated with latest fixes 8.61 1st Sep 2015 ----------------- FIX: Message tracking was not looking through the current days file FIX: Appointment details page stopped working after closing Attendees popup window on iPad FIX: Attachments may not seen in ActiveSync client if they had had content-disposition and no content-type FIX: Using Pacific skin and going to options page doubled up the scrollbars FIX: Indexing node in adminitration program was not being installed for Professional FIX: System messages in webadmin not showing FIX: When removing a postoffice in administration program it was not changing default postoffice settings and bindings FIX: TinyMCE updated to support Windows Edge browser and other various bugs FIX: Footers added to outbound messages could affect DKIM signing FIX: Forward all email under mailbox properties was not removing dirsize.tmp file FIX: Netfxextensibility45 is now detected by Diagnostic Report FIX: Administration program now warns users when configuring the requires authentication option on port 25 FIX: Password recovery for webmail was case sensitive for the username FIX: Indexing (and general parsing of appointments) was not handling attributes with colons in them FIX: ActiveSync was recording _device.xml into wrong directory and ActiveSync admin loads wrong _device.xml when displaying device information FIX: MEInstaller was not properly silent on some errors FIX: Listing devices in ActiveSync administration utility now much faster FIX: POP Retrieval activity log was not logging usernames correctly FIX: Web administration does not load directory entries correctly, so some fields were not displayed FIX: Could not edit directory entry on Windows 2012 in web administration FIX: Webmail does not use global autodiscover options for server, but uses the example.com FIX: Administration program message details page was not showing recipients or sender if an = sign in the address FIX: Administration program much faster creating mailboxes FIX: MEInstaller was crashing if default IIS site was removed FIX: Advanced option page in webmail was not showing when ActiveSync was disabled FIX: Possible error message when requesting a search reindex in administration program FIX: Deleting large batch of messages via EAS on Samsung S4 device causes device to timeout FIX: IMAP UID flag ranges did not work if end of range did not exist FIX: If a list or group only had one member the SMTP EXPN command would return an extra blank line FIX: SMTP service had memory leak on outbound TLS FIX: Webmail fails to display text boundary when no content type is set for message FIX: Webmail is not displaying styles on heading or list tags FIX: Samsung S4 not receiving reply/forward notification flags from server in ActiveSync FIX: In webmail the Free/Busy table could not scroll on iPad FIX: SMTP service could crash on receiving multiple messages in the one connection FIX: Inboxes over 10Gb could cause incorrect mailbox size values when the DIRSIZE.TMP file is rebuilt FIX: In webmail some option pages did not allow scrolling on the iPad FIX: Keyboard appears and disappears in mobile webmail login page for iOS FIX: With webmail you could not add/rename/delete/share folders on iPad FIX: Webmail options page jumps when pressed on menu sub links on iPad & Android FIX: On low disk space the providers may write partial configuration files 8.60 26th Feb 2015 ------------------ FIX: Various webmail security issues (thanks to Soroush Dalili from NCC Group for his work on this) FIX: Quotes in emails may cause problems with the VBScript in SMTP Filters FIX: Web mail client settings page was not displaying global autodiscovery records. FIX: Turkish regional settings on server will remove tags in signatures FIX: Timezones with colons were not escaped properly. Example: TZID=(GMT+01\:00) Amsterdam\, Berlin\, Bern\, Rom\, Stockholm\, Wien - should be TZID="(GMT+01:00) Amsterdam, Berlin, Bern, Rom, Stockholm, Wien":19260126T141856 FIX: ActiveSync (EAS) Sync was returning empty sync response if the same sync key is used (but different request). It should only return an empty response if the request data has not changed. FIX: CalDAV ampersands (and other characters) rendered in xml were being escaped even though the data was in a CDATA section FIX: Appointments generated via old firefox/lightning clients may not be able to be parsed and could corrupt extended characters within data fields 8.59 6th Feb 2015 ------------------ FIX: Bug fixes to vcard and vcalendar encoding (conversions from version 2.1 to version 3) FIX: Webmail was not showing some attachments 8.58 28th Jan 2015 ------------------ ADD: CardDAV now publishes Global Address List (compatible with OpenProtocols Connector) FIX: Inbound SMTP scripts no longer fail on sender/recipient emails with quotes in them FIX: IMAP not longer returns previous folder details on blank SELECT (which may lead to Apple Mail crashing) FIX: CardDAV now handles contacts containing legacy (@) character FIX: Admin not showing sender or recipient address in message details in queues if they contained = symbol FIX: Admin slow creating new mailboxes FIX: Webmail was not showing global autodiscovery settings under client settings FIX: Windows phone may not sync when using ActiveSync FIX: ActiveSync much faster processing sent emails FIX: Possible ActiveSync crash on initial Android sync FIX: Installer could fail to configure web admin if root website did not exist FIX: Advanced options settings page under webmail would not be visibile if ActiveSync was disabled for postoffice 8.57 12th Jan 2015 ------------------ FIX: Admin not showing sender or recipient address in message details in queues if they contained = symbol FIX: Admin slow creating new mailboxes FIX: Webmail was not showing global autodiscovery settings under client settings FIX: Windows phone may not sync when using ActiveSync FIX: ActiveSync much faster processing sent emails FIX: Possible ActiveSync crash on initial Android sync FIX: Installer could fail to configure web admin if root website did not exist 8.56 3rd Dec 2014 ----------------- ADD: Details for queue items in admin has more details and ability to block mailbox authenticating FIX: SMTP had memory leak in outbound TLS and in logging IPv6 addresses FIX: Highlighting links in a plain text email incorrect marks up emails within secure HTML links already marked up FIX: Webmail or indexing could stall on a message FIX: Indexing service may stop indexing, or keep creating extra processing threads FIX: Samsung IMAP client not showing IMAP folder list FIX: TEL tag in VCF file is not being converted to VCARD 3 format when sent to Yosemite client FIX: Long subject or attachment text in webmail was not wrapping, pushing right side of container outside preview pane FIX: Option to automatically change email address when changing a domain name not working FIX: Postoffice connector option for disabling redirections does not work FIX: IE8 & IE7 compatibility improvements for webmail FIX: IMAP could return incorrect HasChildren and HasNoChildren flags FIX: List owner in admin was not compulsory field FIX: Moving some appointment types in webmail calendar by dragging could lock up webmail FIX: Admin outbound mail view send history option was not reading logs that were currently active by the mail services FIX: QP encoded descriptions in CalDAV items may not be decoded fully FIX: Can now manage EAS server cache from within WebMail (same as with SyncML cache) FIX: Added additional Hotmail specific EAS schema extensions to allow the server coupling of the Junk Mail folder FIX: The client configuration page in webmail crashes on some email addresses FIX: When no advert campaign is selected in web admin, advertising banner was showing blank area if advertising enabled FIX: Forwarding a message in web mail does not insert the FROM adddress in the original headers if the FROM has a friendly name FIX: EAS meeting events in calendar may not display the correct time if daylight savings change last week of month FIX: MTA could crash when global spam protection was doing whitelist check and the command file was an NDR with no IP address in it FIX: multipart/relative is handled same as multipart/related for IMAP BODYSTRUCTURE command FIX: HTTPMail Service could crash on some formated calendar items retrieved by CalDAV FIX: Folders that contain the name tasks cannot been seen under root folders in IMAP FIX: Address Resolution Problem after uploading multiple attachents in web mail 8.55 10th Oct 2014 ------------------ ADD: Connection settings for Mail Protocols/Services are now shown under WebMail Options menu (they are either detected or can be configured on a Domain basis). ADD: Added client IP, authenticating user, and authentication status in the queued Message Details window within the MMC Admin. ADD: Added Block IP to the MMC Admin queued Message Details screen (so you can block the client IP address from connecting to the SMTP service) ADD: Added Disable Mailbox from the queued Message Details screen (an administrator can disable a mailbox directly from the Message Details screen) ADD: Added View Send History (so an administrator can view the send history from within the queued Message Details screen) ADD: Added ability to disable Basic authentication for Synchronisation Protocols ADD: Added Digest authentication for all Synchronisation Protocols (specifically for CalDAV/CardDAV since Apple devices with current OSX releases require it) ADD: Header and Footer Management is now available under WebAdmin IMP: Added additional authentication credential caching to significantly improve the responsiveness of authenticating users IMP: Improved handing of Ping Collisions to reduce bandwidth when using ActiveSync with Outlook 2013 FIX: When sending a meeting request to a mailbox which is synced via EAS in Outlook 2013, the meeting request is synced as a message rather th a meeting request. FIX: Contact photos may not render when downloaded via clients requesting VCARD Version 3 (CardDAV on OSX) FIX: ActiveSync may not clear all device settings/state configuration when device is reconfigured (potentially causing duplicates in Microsoft Outlook/EAS) FIX: Photo encoding for CardDAV where VCard boundaries may not be converted property from Version 2.1 to Version 3.0 (and vice versa) FIX: VCF files directly copied to Contacts folder would not display if the .VCF extension was in lower case FIX: Blank E-mail messages with only an attachment would not save to Drafts Folder FIX: ActiveSync would not use Mailbox TimeZone setting as the default when viewing Free and Busy times of All Day Events FIX: Updating the status via a scheduling response in WebMail would not always be able to locate the original message (in cases where the Appointment UID was wrapped) FIX: MTA may raise a null pointer exception if connecting client IP address was not populated (by third party connectors or filter actions) FIX: SYSADMIN could configure services (like SMS) that were not available in Professional Edition 8.54 18th Sep 2014 ------------------ IMP: Added additional caching of store change list to improve EAS performance with Outlook IMP: Minor layout improvements to Web Administration FIX: CardDAV on OSX would not process all vCards FIX: Samsung S4 (EAS) loses message after moving message to a new sub folder and resyncing FIX: WebAdmin: fixed height rendering issue during loading, where content intially appears vertically cramped FIX: Contacts Photos may be removed when edited via WebMail (depending on the format of the VCARD) FIX: Professional install does not put all services into 64bit FIX: SMTP Inbound will truncate recipient list when the Maximum Recipient Threshold is reached (rather than reporting an error to the client) FIX: Changed the ordering of EAS XML responses since WP8 seems to require specific ordering (any changes that occur while synchronising may cause sync error) FIX: HTML signatures are now converted to plain text if they were composed as HTML, but the plain text editor is selected. 8.53 3rd Sep 2014 ----------------- ADD: Option screen now allows you do define a default point size of HTML editor IMP: Improved the resilience of Outlook 2013 ActiveSync synchronisation IMP: Improved the speed and resource usage when synchronising large mailboxes via EAS IMP: Improved the layout and content of the services overview screen when accessing the Synchonisation Service URL IMP: ActiveSync now implements the Preview field when it is requested FIX: Updated HTML Editor to latest version of TinyMCE FIX: ICS/iCalendar Sharing will not allow access to shared mailbox calendars FIX: Some messages could not be blacklisted/whitelisted from message list right click menu FIX: Outlook EAS is would not immediate sync nested subfolders until the client was reopened. FIX: Setting a POP retrieval entry to disabled when using MySQL or SQL Server does not disable it unless you remove it. FIX: Improved the HTML parsing of webmail messages (some messages/tags would be stripped when they did not need to be) FIX: EAS was not sending down the correct TZ recurrence information FIX: Diagnostic utility did not report URL blacklisting status FIX: MailEnable could attempt to create connection reporting files for IMAP,POP and SMTP in root drive (if the registry key was not defined) FIX: The iOS configuration screen on small devices was not scaled correctly FIX: Webmail upload limit property page in admin would crash if the maximum allowed content length was over 1gb FIX: Spellcheck configuration options missing in Professional 8.52 5th Aug 2014 ----------------- IMP: Message tracker application has been updated to make it consistent with the version in the MMC IMP: MailEnable now adds Auto-Submitted: auto-replied header to autoresponders IMP: MailEnable no longer requires .Net 2/3.5 to be installed on systems that support .NET 4 (and later) IMP: TinyMCE Editor updated to current release (with various fixes and improvements, mainly related to IE 11) IMP: Web security token files were being written to the root of the config directory (this has been moved to a more suitable location) IMP: An autoresponder now logs to the postoffice connector debug log that it fired FIX: POP Non-SSL connection is made to POP on SSL port does not respect session timeout settings FIX: IMAP was returning PERMANENT FLAGS full response for EXAMINE command FIX: IMAP IDLE after selecting a mailbox with EXAMINE, notifications are not received for the connection FIX: Updated invalid SMTP firewall exceptions on initial install FIX: Disabling a list in the MMC via the folder tree does not disable it. FIX: Entering local email addresses for the domain properties abuse@, etc in MMC admin causes looping FIX: Exception thrown in MMC when changing webmail default postoffice FIX: IMAP may not accept connections immediately when service is restarted FIX: EAS calendar issues with Samsung devices. Floating time calendar entries (created on Mac) are not displayed on the device FIX: SMTP may deliver delay status notifications to some recipients when the message was able to be received (but other recipients failed) FIX: BlockFileLock Activity notification handler (WaitForAccessToFile) failed to obtain a lock on the blockfile may be misreported in Windows Event Log FIX: MailEnable Indexing service may exhibit high CPU when restarted and may not update its Starting status under the Services control panel applet FIX: Windows 8 mobile device via EAS may not display a new contact immediately after it has been added. FIX: Disabling a mailbox in new MMC admin is not disabling login FIX: Workaround for Cisco SMTP proxy misbehaviour (to overcome problem sending via SMTP proxy) FIX: Large UID COPY IMAP command could cause high CPU FIX: ActiveSync Windows Phone may display synchronisation error upon account creation FIX: Professional Edition Management Console did not allow you to configure Spell Checking Options IMP: "Empty Folder" option within webmail does not immediately update mailbox usage 8.51 11th Jun 2014 ------------------ FIX: Added link/url button for new editor in webmail FIX: Editor Languages will now work with button label translations FIX: Reduced the efficiency and behaviour of the indexing service IMP: Significantly reduced memory footprint of IMAP service FIX: Core services may leak memory over time FIX: IMAP AUTH LOGIN was returning BAD instead of NO for invalid password FIX: IMAP CRAM-MD5 returned text for failed logins is improved FIX: Removed TinyMCE popup menu to allow browser copy/paste and spell check FIX: IMAP NOOP command may place additional load on server if folder is marked with changes (via _change.dty file) FIX: WebAdmin welcome page would displays links to some options even if they are disabled FIX: WebAdmin was not creating mailbox special folders upon creation FIX: Autoresponder now logs to the postoffice connector debug log that it fired FIX: Right click action for disabling a mailbox in new MMC Admin was not also disabling login FIX: Improved the layout and function of the port bindings for SMTP Connector within the MMC Admin FIX: Accepting meeting change in webmail was not updating the VCAL times in the underlying appointment data (VCALENDAR) FIX: Forwarding a message in webmail would not add Message-Id header when generating compound message FIX: ActiveSync will now permit previous sync key re-use when no changes have been detected (reducing the need to resync folders upon communication error) ADD: Ability to have a global autodiscover configuration file (which is used when domain specific settings are not supplied) 8.50 8th May 2014 ------------------ ADD: New Mailbox Indexing Engine/Service and associated indexing transaction management ADD: WebMail - ability to search accross entire mailbox for messages, contacts, notes, tasks, appointments, etc ADD: Mobile WebMail - ability to search accross entire mailbox for messages, contacts, notes, tasks, appointments, etc IMP: Improved layout of login screen ADD: Added support for new TinyMCE editor (as an alternative to FreeTextBox) IMP: Reduced the size of core Desktop WebMail web pages ADD: Web Administration now provides access to System Messages interface ADD: Web Administration now provides access to Diagnostic Report ADD: Web Administration now provides access to IMAP, SMTP, MTA, POP3 and Postoffice Connector log files (allowing them to be downloaded in zipped format) ADD: Web Administration now provides access to System Message Tracking (allowing analysis of message delivery and routing) ADD: New wizard for configuring ActiveSync and Autodiscovery FIX: ActiveSync would not encode 7bit attachments in base64 format (which is a requirement of EAS) 8.04 23rd Mar 2014 ------------------ IMP: ActiveSync will now handle and retransmit stateful updates if a loss of sync state occurs IMP: Tracking utility did not show filter actions or MTA diagnostic information FIX: Disabling filter in new mailenable management console would not disable FIX: ActiveSync did not add friendly name to From header if it is missing when attempting to send FIX: The option to check spelling of webmail messages before being sent was not working FIX: Webmail allowed users to redirect to themselves FIX: Professional installer was not adding the SMTP mailbox blacklisting status reg key (and did not activate mailbox blacklisting) 8.03 3rd Mar 2014 ----------------- FIX: IMAP will now queue notifications for dispatch under idle rather than dispatching them during idle FIX: IMAP may raise exceptions when signalling other connections (leading to a restart of the IMAP exception) FIX: Meeting request with timezone offsets comprised with a partial 30 minute offset would ignore the 30 minute offset. FIX: WebAdmin did not respect default value for maximum mailbox size postoffice setting FIX: ActiveSync will now attempt to throttle the maximum response size to 20MB FIX: ActiveSync will now use incremental SyncKeys to protect agains communication failure when processing MoreAvailable (typically occurs when initially loading large mailboxes with Outlook) 8.02 20th Feb 2014 ------------------ FIX: Web Admin will now work correctly with IE 11 (previous versions would not detect new IE Version) FIX: POP service may log exception when trying to log abuse detection entries FIX: Mobile WebMail was not being installed in a fresh Professional Edition installation. FIX: Professional Edition would not configure 64 bit services FIX: MEInstaller may raise DLL exceptions when installing and configuring WebMail or WebAdmin FIX: MEInstaller did not add members to IME_STORE_GROUP group FIX: Settings associated with Application Pools configured to run with Version 4.x of the framework are now maintained. 8.01 22nd Jan 2014 ------------------ ADD: ActiveSync and Outlook schema responses for Autodiscovery are now able to be customised seperately per domain IMP: SpamAssassin diagnostics will now report on the Status of the SpamAssassin service. IMP: Added additional fields to items report back in Global Address List via ActiveSync FIX: Slow resource leak may occur in IMAP (and EAS) when copying items to another folder. FIX: Server would continue to log SpamAssassin connection error even after detecting that it is not available. FIX: Enabling or disabling system messages notifications in alerter generated error email FIX: MMC crashes when creating a custom list subscription notification FIX: In the administration program on the status page, clicking a column header in the news listview crashed MMC FIX: WebAdmin branding would not work for domains that contained .net FIX: Creating DKIM selector for first time did not save it as active even though the checkbox is selected FIX: Stats page in webmail did not have a scrollbar 8.00 26th Nov 2013 ------------------ INF: Initial release of features as at http://www.mailenable.com/version8