Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Fedora 31: FEDORA-2019-e080507ba5 Critical: Exim Buffer Overflow

fedora
Calendar Grey October 6, 2019
Dist Fedora Esm H88
Resolve address buffer overflow issue in Exim on Fedora 31, addressing CVE-2019-16928 to improve security protocols.
This is an update fixing CVE-2019-16928.

Summary

Exim is a message transfer agent (MTA) developed at the University of

Cambridge for use on Unix systems connected to the Internet. It is

freely available under the terms of the GNU General Public Licence. In

style it is similar to Smail 3, but its facilities are more

general. There is a great deal of flexibility in the way mail can be

routed, and there are extensive facilities for checking incoming

mail. Exim can be installed in place of sendmail, although the

configuration of exim is quite different to that of sendmail.

This is an update fixing CVE-2019-16928.

[ 1 ] Bug #1756930 - CVE-2019-16928 exim: remotely triggerable buffer overflow in string_vformat()

https://bugzilla.redhat.com/show_bug.cgi?id=1756930

su -c 'dnf upgrade --advisory FEDORA-2019-e080507ba5' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 4.92.3
Release: 1.fc31
Summary: The exim mail transfer agent

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here