Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 27: 2017-0053bb9719 High: Exim DoS And Use-After-Free

fedora
Calendar Grey December 12, 2017
Dist Fedora Esm H88
Patch released for Fedora 27 addressing security vulnerabilities including denial of service and use-after-free complications in the Exim mail transfer program.
This is an update fixing denial of service (CVE-2017-16944)

Summary

Exim is a message transfer agent (MTA) developed at the University of

Cambridge for use on Unix systems connected to the Internet. It is

freely available under the terms of the GNU General Public Licence. In

style it is similar to Smail 3, but its facilities are more

general. There is a great deal of flexibility in the way mail can be

routed, and there are extensive facilities for checking incoming

mail. Exim can be installed in place of sendmail, although the

configuration of exim is quite different to that of sendmail.

This is an update fixing denial of service (CVE-2017-16944). ---- This is an

update fixing use-after-free (CVE-2017-16943).

[ 1 ] Bug #1517566 - Exim: remote code execution if chunking is enabled (CVE-2017-16943)

https://bugzilla.redhat.com/show_bug.cgi?id=1517566

su -c 'dnf upgrade exim' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 27
Version: 4.89
Release: 7.fc27
Summary: The exim mail transfer agent

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here