This update for exim fixes the following issues:
Exim was updated to exim-4.94.2
security update (boo#1185631)
* CVE-2020-28007: Link attack in Exim's log directory
* CVE-2020-28008: Assorted attacks in Exim's spool directory
* CVE-2020-28014: Arbitrary PID file creation
* CVE-2020-28011: Heap buffer overflow in queue_run()
* CVE-2020-28010: Heap out-of-bounds write in main()
* CVE-2020-28013: Heap buffer overflow in parse_fix_phrase()
* CVE-2020-28016: Heap out-of-bounds write in parse_fix_phrase()
* CVE-2020-28015: New-line injection into spool header file (local)
* CVE-2020-28012: Missing close-on-exec flag for privileged pipe
* CVE-2020-28009: Integer overflow in get_stdinput()
* CVE-2020-28017: Integer overflow in receive_add_recipient()
* CVE-2020-28020: Integer overflow in receive_msg()
* CVE-2020-28023: Out-of-bounds read in smtp_setup_msg()
* CVE-2020-28021: New-line injection into spool...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-677=1
- openSUSE Leap 15.2 (x86_64):
exim-4.94.2-lp152.8.3.1
exim-debuginfo-4.94.2-lp152.8.3.1
exim-debugsource-4.94.2-lp152.8.3.1
eximon-4.94.2-lp152.8.3.1
eximon-debuginfo-4.94.2-lp152.8.3.1
eximstats-html-4.94.2-lp152.8.3.1
https://www.suse.com/security/cve/CVE-2017-1000369.html
https://www.suse.com/security/cve/CVE-2017-16943.html
https://www.suse.com/security/cve/CVE-2017-16944.html
https://www.suse.com/security/cve/CVE-2018-6789.html
https://www.suse.com/security/cve/CVE-2019-16928.html
https://www.suse.com/security/cve/CVE-2020-12783.html
https://www.suse.com/security/cve/CVE-2020-28007.html
https://www.suse.com/security/cve/CVE-2020-28008.html
https://www.suse.com/security/cve/CVE-2020-28009.html
https://www.suse.com/security/cve/CVE-2020-28010.html
https://www.suse.com/security/cve/CVE-2020-28011.html
https://www.suse.com/security/cve/CVE-2020-28012.html
https://www.suse.com/security/cve/CVE-2020-28013.html
https://www.suse.com/security/cve/CVE-2020-28014.html
https://www.suse.com/security/cve/CVE-2020-28015.html
https://www.suse.com/security/cve/CVE-2020-28016.html
https://www.suse.com/security/cve/CVE-2020-28017.html
https://www.suse.com/security/cve/CVE-2020-28018.html
https://www.suse.com/security/cve/CVE-2020-28...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.