Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 40: FEDORA-2025-e694138ac5 critical: exim remote SQL injection

fedora
Calendar Grey March 5, 2025
Dist Fedora Esm H88
This Debian notice outlines an urgent patch for postfix dealing with a remote code execution vulnerability.
This is an update fixing possible remote SQL injection.

Summary

Exim is a message transfer agent (MTA) developed at the University of

Cambridge for use on Unix systems connected to the Internet. It is

freely available under the terms of the GNU General Public Licence. In

style it is similar to Smail 3, but its facilities are more

general. There is a great deal of flexibility in the way mail can be

routed, and there are extensive facilities for checking incoming

mail. Exim can be installed in place of sendmail, although the

configuration of exim is quite different to that of sendmail.

Update Information:

This is an update fixing possible remote SQL injection.

Change Log

* Mon Feb 24 2025 Jaroslav Å karvada - 4.98.1-1 - New version Resolves: rhbz#2346977 - Fixed possible remote SQL injection Resolves: CVE-2025-26794 - Updated exim maintainers keyring

References


[ 1 ] Bug #2346977 - exim-4.98.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2346977 [ 2 ] Bug #2347249 - CVE-2025-26794 exim: Exim: remote SQL injection [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2347249

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e694138ac5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: exim
Product: Fedora 40
Version: 4.98.1
Release: 1.fc40
Summary: The exim mail transfer agent

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here