Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE: 2024:0007-1 important: exim smtp security fix

opensuse
Calendar Grey January 4, 2024
Dist Opensuse Esm H88
An important update for openSUSE addresses multiple exim security issues and fixes 7 vulnerabilities.
An update that fixes 7 vulnerabilities is now available

Description

This update for exim fixes the following issues:

exim was updated to 4.97.1 (boo#1218387, CVE-2023-51766):

* Fixes for the smtp protocol smuggling (CVE-2023-51766)

exim was updated to exim 4.96:

* Move from using the pcre library to pcre2.

* Constification work in the filters module required a major version

bump for the local-scan API. Specifically, the "headers_charset"

global which is visible via the API is now const and may therefore not

be modified by local-scan code.

* Bug 2819: speed up command-line messages being read in. Previously a

time check was being done for every character; replace that with one

per buffer.

* Bug 2815: Fix ALPN sent by server under OpenSSL. Previously the

string sent was prefixed with a length byte.

* Change the SMTP feature name for pipelining connect to be compliant

with RFC 5321. Previously Dovecot (at least) would log errors during

submission.

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2024-7=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64):

exim-4.97.1-bp155.5.9.1

eximon-4.97.1-bp155.5.9.1

eximstats-html-4.97.1-bp155.5.9.1

References

https://www.suse.com/security/cve/CVE-2022-3559.html

https://www.suse.com/security/cve/CVE-2023-42114.html

https://www.suse.com/security/cve/CVE-2023-42115.html

https://www.suse.com/security/cve/CVE-2023-42116.html

https://www.suse.com/security/cve/CVE-2023-42117.html

https://www.suse.com/security/cve/CVE-2023-42119.html

https://www.suse.com/security/cve/CVE-2023-51766.html

https://bugzilla.suse.com/1218387

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2024:0007-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here