exim4 4.92-8+deb10u6 source package in Debian

Changelog

exim4 (4.92-8+deb10u6) buster-security; urgency=high

  * Fix several security vulnerabilities reported by Qualys and add related
    robustness improvements. (Originally fixed in upstream release 4.94.3 and
    in upstream GIT branch exim-4.92.3+fixes. (Special thanks to Heiko)
    + CVE-2020-28025: Heap out-of-bounds read in pdkim_finish_bodyhash()
    + CVE-2020-28018: Use-after-free in tls-openssl.c
    + CVE-2020-28023: Out-of-bounds read in smtp_setup_msg()
    + CVE-2020-28010: Heap out-of-bounds write in main()
    + CVE-2020-28011: Heap buffer overflow in queue_run()
    + CVE-2020-28013: Heap buffer overflow in parse_fix_phrase()
    + CVE-2020-28017: Integer overflow in receive_add_recipient()
    + CVE-2020-28022: Heap out-of-bounds read and write in extract_option()
    + CVE-2020-28026: Line truncation and injection in spool_read_header()
    + CVE-2020-28015 and CVE-2020-28021: New-line injection into spool header
      file.
    + CVE-2020-28009: Integer overflow in get_stdinput()
    + CVE-2020-28024: Heap buffer underflow in smtp_ungetc()
    + CVE-2020-28012: Missing close-on-exec flag for privileged pipe
    + CVE-2020-28019: Failure to reset function pointer after BDAT error
    + CVE-2020-28007: Link attack in Exim's log directory
    + CVE-2020-28008: Assorted attacks in Exim's spool directory
    + CVE-2020-28014, CVE-2021-27216: Arbitrary PID file creation, clobbering,
      and deletion.

 -- Andreas Metzler <email address hidden>  Sat, 01 May 2021 11:42:39 +0200

Upload details

Uploaded by:
Exim4 Maintainers
Uploaded to:
Buster
Original maintainer:
Exim4 Maintainers
Architectures:
any all
Section:
mail
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section
Buster release main mail

Builds

Downloads

File Size SHA-256 Checksum
exim4_4.92-8+deb10u6.dsc 2.8 KiB e9bf1b8c6c04ab556b5b6e9badcffb8f4e1dfd6a41c9645acd7328ddcb70fe93
exim4_4.92.orig.tar.xz 1.7 MiB 6ac9e62b484e78951c7c0517d1229ad7619a7eea70ca3b38b8ef430b28ef1d62
exim4_4.92.orig.tar.xz.asc 488 bytes 2d0cbdce4ca1d5f8850a5335e2f7dc25c229c260b533220f1e647c746f8ad1d9
exim4_4.92-8+deb10u6.debian.tar.xz 485.6 KiB 485766d69f748d3b3a4b4318571c4d830c7dcc7c91113ede0115ac3c8b1db9d0

No changes file available.

Binary packages built by this source