Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian 3.0: DSA 502-1 Moderate: Exim-TLS Buffer Overflow Risk

debian
Calendar Grey May 12, 2004
Debian Logo
Key instructions to address buffer overflow risks in Exim-TLS on Debian, ensuring system security and stability.
These can not be exploited with the default configuration from the Debian system.

Summary

Georgi Guninski discovered two stack-based buffer overflows in exim
and exim-tls. They can not be exploited with the default
configuration from the Debian system, though. The Common
Vulnerabilities and Exposures project identifies the following
problems that are fixed with this update:

CAN-2004-0399

When "sender_verify = true" is configured in exim.conf a buffer
overflow can happen during verification of the sender. This
problem is fixed in exim 4.

CAN-2004-0400

When headers_check_syntax is configured in exim.conf a buffer
overflow can happen during the header check. This problem does
also exist in exim 4.

For the stable distribution (woody) these problems have been fixed in
version 3.35-3woody2.

The unstable distribution (sid) does not contain exim-tls anymore.
The functionality has been incorporated in the main exim versions
which have these problems fixed in version 3.36-11 for exim 3 and in
version 4.33-1 for exim 4.

We recommend that you upgrade your exim-tls package.


U...

Read the Full Advisory

Package: exim-tls
CVE ID: CAN-2004-0399 CAN-2004-0400

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here