Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 449
Alerts This Week
Warning Icon 1 449

Debian Exim-TLS Moderate Buffer Overflow Vulnerability Advisory DSA 502-1

debian
Calendar Grey May 12, 2004
Scroller Debian
Debian Exim-TLS moderate buffer overflow risk advisory details upgrade instructions for exim-tls package and security.
These can not be exploited with the default configuration from the Debian system.

Summary

Georgi Guninski discovered two stack-based buffer overflows in exim
and exim-tls. They can not be exploited with the default
configuration from the Debian system, though. The Common
Vulnerabilities and Exposures project identifies the following
problems that are fixed with this update:

CAN-2004-0399

When "sender_verify = true" is configured in exim.conf a buffer
overflow can happen during verification of the sender. This
problem is fixed in exim 4.

CAN-2004-0400

When headers_check_syntax is configured in exim.conf a buffer
overflow can happen during the header check. This problem does
also exist in exim 4.

For the stable distribution (woody) these problems have been fixed in
version 3.35-3woody2.

The unstable distribution (sid) does not contain exim-tls anymore.
The functionality has been incorporated in the main exim versions
which have these problems fixed in version 3.36-11 for exim 3 and in
version 4.33-1 for exim 4.

We recommend that you upgrade your exim-tls package.


U...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: exim-tls
CVE ID: CAN-2004-0399 CAN-2004-0400

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.