This is new version of exim fixing some security bugs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c23e1d19d2 2026-05-10 03:04:49.565385+00:00 -------------------------------------------------------------------------------- Name : exim Product : Fedora 43 Version : 4.99.2 Release : 1.fc43 URL : https://www.exim.org/ Summary : The exim mail transfer agent Description : Exim is a message transfer agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet. It is freely available under the terms of the GNU General Public Licence. In style it is similar to Smail 3, but its facilities are more general. There is a great deal of flexibility in the way mail can be routed, and there are extensive facilities for checking incoming mail. Exim can be installed in place of sendmail, although the configuration of exim is quite different to that of sendmail. -------------------------------------------------------------------------------- Update Information: This is new version of exim fixing some security bugs. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 30 2026 Jaroslav \u0160karvada - 4.99.2-1 - New version Resolves: rhbz#2463798 - Refreshed keyring * Mon Jan 19 2026 Jaroslav \u0160karvada - 4.99.1-3 - Dummy rebuild to check the CI functionality * Fri Jan 16 2026 Fedora Release Engineering - 4.99.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2463798 - exim-4.99.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2463798 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c23e1d19d2' at the command line. For more information,refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 43 exim focuses on security fixes to enhance reliability and operational integrity.. Fedora exim update mail transfer agent security patch. . Severity: Important. LinuxSecurity.com Team
This is an update fixing CVE 2025-30232.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ab7148736c 2025-04-05 01:25:14.172330+00:00 -------------------------------------------------------------------------------- Name : exim Product : Fedora 41 Version : 4.98.2 Release : 1.fc41 URL : https://www.exim.org/ Summary : The exim mail transfer agent Description : Exim is a message transfer agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet. It is freely available under the terms of the GNU General Public Licence. In style it is similar to Smail 3, but its facilities are more general. There is a great deal of flexibility in the way mail can be routed, and there are extensive facilities for checking incoming mail. Exim can be installed in place of sendmail, although the configuration of exim is quite different to that of sendmail. -------------------------------------------------------------------------------- Update Information: This is an update fixing CVE 2025-30232. -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 26 2025 Jaroslav Å karvada - 4.98.2-1 - New version Resolves: CVE 2025-30232 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2355644 - CVE-2025-30232 exim: privilege escalation via use-after-free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2355644 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ab7148736c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . New Fedora 41 patch tackles CVE 2025-30233 related to the exim mail transfer service, fixing a serious vulnerability.. exim mail transfer agent,Fedora update,CVE 2025-30232,system security,privilege escalation. . Severity: Critical. LinuxSecurity.com Team
This is an update fixing CVE-2019-16928.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-e080507ba5 2019-10-07 00:00:39.742614 --------------------------------------------------------------------------------Name : exim Product : Fedora 31 Version : 4.92.3 Release : 1.fc31 URL : https://www.exim.org/ Summary : The exim mail transfer agent Description : Exim is a message transfer agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet. It is freely available under the terms of the GNU General Public Licence. In style it is similar to Smail 3, but its facilities are more general. There is a great deal of flexibility in the way mail can be routed, and there are extensive facilities for checking incoming mail. Exim can be installed in place of sendmail, although the configuration of exim is quite different to that of sendmail. --------------------------------------------------------------------------------Update Information: This is an update fixing CVE-2019-16928. --------------------------------------------------------------------------------References: [ 1 ] Bug #1756930 - CVE-2019-16928 exim: remotely triggerable buffer overflow in string_vformat() https://bugzilla.redhat.com/show_bug.cgi?id=1756930 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-e080507ba5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
This is an update fixing multiple memory leaks and other problems.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f5177f3a16 2017-08-31 13:59:46.566618 --------------------------------------------------------------------------------Name : exim Product : Fedora 26 Version : 4.89 Release : 5.fc26 URL : https://www.exim.org/ Summary : The exim mail transfer agent Description : Exim is a message transfer agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet. It is freely available under the terms of the GNU General Public Licence. In style it is similar to Smail 3, but its facilities are more general. There is a great deal of flexibility in the way mail can be routed, and there are extensive facilities for checking incoming mail. Exim can be installed in place of sendmail, although the configuration of exim is quite different to that of sendmail. --------------------------------------------------------------------------------Update Information: This is an update fixing multiple memory leaks and other problems. --------------------------------------------------------------------------------References: [ 1 ] Bug #1457748 - CVE-2017-1000369 Exim: Privilege escalation via multiple memory leaks https://bugzilla.redhat.com/show_bug.cgi?id=1457748 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade exim' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announcemailing list --
A local root privilege escalation vulnerability was found in Exim, Debian's default mail transfer agent, in configurations using the 'perl_startup' option (Only Exim via exim4-daemon-heavy enables Perl support). . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3517-1
This is new version fixing local privilege escalation for set-uid root when using perl_startup.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-e062971917 2016-03-12 07:58:13.669760 -------------------------------------------------------------------------------- Name : exim Product : Fedora 23 Version : 4.86.2 Release : 1.fc23 URL : https://www.exim.org/ Summary : The exim mail transfer agent Description : Exim is a message transfer agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet. It is freely available under the terms of the GNU General Public Licence. In style it is similar to Smail 3, but its facilities are more general. There is a great deal of flexibility in the way mail can be routed, and there are extensive facilities for checking incoming mail. Exim can be installed in place of sendmail, although the configuration of exim is quite different to that of sendmail. -------------------------------------------------------------------------------- Update Information: This is new version fixing local privilege escalation for set-uid root when using perl_startup. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1314293 - CVE-2016-1531 exim: local root privilege escalation for configurations with perl_startup https://bugzilla.redhat.com/show_bug.cgi?id=1314293 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update exim' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
This erratum fixes two relatively minor security issues which were discovered in Exim in the last few weeks. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2005-0021 and CAN-2005-0022 to these, respectively.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-001 2005-01-06 ---------------------------------------------------------------------Product : Fedora Core 3 Name : exim Version : 4.43 Release : 1.FC3.1 Summary : The exim mail transfer agent Description : Exim is a mail transport agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet. In style it is similar to Smail 3, but its facilities are more extensive, and in particular it has options for verifying incoming sender and recipient addresses, for refusing mail from specified hosts, networks, or senders, and for controlling mail relaying. Exim is in production use at quite a few sites, some of which move hundreds of thousands of messages per day. Exiscan is compiled in to allow inbuilt scanning capability. See https://duncanthrax.net/exiscan-acl/ ---------------------------------------------------------------------Update Information: This erratum fixes two relatively minor security issues which were discovered in Exim in the last few weeks. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2005-0021 and CAN-2005-0022 to these, respectively. 1. The function host_aton() can overflow a buffer if it is presented with an illegal IPv6 address that has more than 8 components. 2. The second report described a buffer overflow in the function spa_base64_to_bits(), which is part of the code for SPA authentication. This code originated in the Samba project. The overflow can be exploited only if you are using SPAauthentication. ---------------------------------------------------------------------* Tue Jan 04 2005 David Woodhouse 4.43-1.FC3.1 - Fix buffer overflows (CAN-2005-0021, CAN-2005-0022) - Demonstrate SASL auth configuration in default config file - Enable TLS and provide certificate if necessary - Don't reject all GB2312 charset mail by default ---------------------------------------------------------------------This update can be downloaded from: f4cafadca104a85ff5f31cbf5ca4c4f1 SRPMS/exim-4.43-1.FC3.1.src.rpm 3412f5b4cf40ad504dbaf2b7e2fffa62 x86_64/exim-4.43-1.FC3.1.x86_64.rpm 1446c41e65cfd6f15ae60b969ab3d20c x86_64/exim-mon-4.43-1.FC3.1.x86_64.rpm e71be8446d9e4d250ca40a41c2d7b49a x86_64/exim-doc-4.43-1.FC3.1.x86_64.rpm 1d515c5be494e657333549f72f4621e2 x86_64/exim-sa-4.43-1.FC3.1.x86_64.rpm bcd320d0c2f88911a3ccc02b95cb2843 x86_64/debug/exim-debuginfo-4.43-1.FC3.1.x86_64.rpm 7c2205113fe3285a76b797748845548b i386/exim-4.43-1.FC3.1.i386.rpm 8227e5701319639057b951bc45bbecf8 i386/exim-mon-4.43-1.FC3.1.i386.rpm 3b7e2741f4208757e92ab2d228b1fe8a i386/exim-doc-4.43-1.FC3.1.i386.rpm 4e5cbfea028184d6710443a3c0e79c29 i386/exim-sa-4.43-1.FC3.1.i386.rpm 9c2c6e5d633104ca71bf80b062e9f0a2 i386/debug/exim-debuginfo-4.43-1.FC3.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Megyer Laszlo found a printf format bug in the exim mail transferagent. The code that checks the header syntax of an email logsan error without protecting itself against printf format attacks.. ------------------------------------------------------------------------ Debian Security Advisory DSA-058-1
Get the latest Linux and open source security news straight to your inbox.