- -------------------------------------------------------------------------
Debian Security Advisory DSA-3747-1                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
December 25, 2016                     https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : exim4
CVE ID         : CVE-2016-9963

Bjoern Jacke discovered that Exim, Debian's default mail transfer agent,
may leak the private DKIM signing key to the log files if specific
configuration options are met.

For the stable distribution (jessie), this problem has been fixed in
version 4.84.2-2+deb8u2.

We recommend that you upgrade your exim4 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Debian: DSA-3747-1: exim4 security update

December 25, 2016
Bjoern Jacke discovered that Exim, Debian's default mail transfer agent, may leak the private DKIM signing key to the log files if specific configuration options are met

Summary

For the stable distribution (jessie), this problem has been fixed in
version 4.84.2-2+deb8u2.

We recommend that you upgrade your exim4 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Severity
Bjoern Jacke discovered that Exim, Debian's default mail transfer agent,
may leak the private DKIM signing key to the log files if specific
configuration options are met.

Related News