Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
197

Debian 11: DLA-3938-1 critical: exim4 code execution and info disclosure

Multiple potential security vulnerabilities have been addressed in exim4, a mail transport agent. These issues may allow remote attackers to disclose sensitive information or execute arbitrary code but only if Exim4 is run behind or with untrusted proxy servers or DNS resolvers. If your proxy-protocol proxy . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3938-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany October 29, 2024 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : exim4 Version : 4.94.2-7+deb11u4 CVE ID : CVE-2021-38371 CVE-2022-3559 CVE-2023-42117 CVE-2023-42119 Debian Bug : 992172 Multiple potential security vulnerabilities have been addressed in exim4, a mail transport agent. These issues may allow remote attackers to disclose sensitive information or execute arbitrary code but only if Exim4 is run behind or with untrusted proxy servers or DNS resolvers. If your proxy-protocol proxy or DNS resolver are trustworthy, you are not affected. For Debian 11 bullseye, these problems have been fixed in version 4.94.2-7+deb11u4. We recommend that you upgrade your exim4 packages. For the detailed security status of exim4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/exim4 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5107-1 reveals vulnerabilities in openssl. It is recommended to update systems to prevent unauthorized data access.. Debian LTS, exim4, security advisory, mail transport. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 29, 2024 Critical Debian LTS
87

Debian: DSA-5597-1 Critical: Exim4 Message Embedding Flaw

It was discovered that Exim, a mail transport agent, can be induced to accept a second message embedded as part of the body of a first message in certain configurations where PIPELINING or CHUNKING on incoming connections is offered. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5597-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso January 04, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : exim4 CVE ID : CVE-2023-51766 Debian Bug : 1059387 It was discovered that Exim, a mail transport agent, can be induced to accept a second message embedded as part of the body of a first message in certain configurations where PIPELINING or CHUNKING on incoming connections is offered. For the oldstable distribution (bullseye), this problem has been fixed in version 4.94.2-7+deb11u2. For the stable distribution (bookworm), this problem has been fixed in version 4.96-15+deb12u4. We recommend that you upgrade your exim4 packages. For the detailed security status of exim4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/exim4 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Advisory DSA-5597-1 addresses a critical flaw in Exim4 that allows message embedding in emails.. Exim4 Security Update, Debian Advisory, Email Agent Security, Transport Layer Issues, Message Handling Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 04, 2024 Critical Debian
172

Ubuntu 16.04 ESM: USN-4934-2 Critical: Exim Denial Of Service

Several security issues were fixed in Exim.. =========================================================================Ubuntu Security Notice USN-4934-2 May 06, 2021 exim4 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Several security issues were fixed in Exim. Software Description: - exim4: Exim is a mail transport agent Details: USN-4934-1 fixed several vulnerabilities in Exim. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. CVE-2020-28026 only affected Ubuntu 16.04 ESM. Original advisory details: It was discovered that Exim contained multiple security issues. An attacker could use these issues to cause a denial of service, execute arbitrary code remotely, obtain sensitive information, or escalate local privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: exim4-base 4.86.2-2ubuntu2.6+esm1 exim4-daemon-heavy 4.86.2-2ubuntu2.6+esm1 exim4-daemon-light 4.86.2-2ubuntu2.6+esm1 Ubuntu 14.04 ESM: exim4-base 4.82-3ubuntu2.4+esm3 exim4-daemon-heavy 4.82-3ubuntu2.4+esm3 exim4-daemon-light 4.82-3ubuntu2.4+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4934-2 https://ubuntu.com/security/notices/USN-4934-1 CVE-2020-28007, CVE-2020-28008, CVE-2020-28009, CVE-2020-28011, CVE-2020-28012, CVE-2020-28013, CVE-2020-28014, CVE-2020-28015, CVE-2020-28016, CVE-2020-28017, CVE-2020-28020, CVE-2020-28022, CVE-2020-28024, CVE-2020-28025, CVE-2020-28026, CVE-2021-27216 . Multiple security issues in Exim addressed by Ubuntu advisory 4934-2, impacting versions 14.04 and 16.04 ESM.. Exim Fix, Denial Of Service, Ubuntu Security Notice. .Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 06, 2021 Critical Ubuntu
98

Red Hat: RHSA-2011:0422-01 Moderate: Postfix TLS Security Update

Updated postfix packages that fix two security issues are now available for Red Hat Enterprise Linux 4 and 5. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: postfix security update Advisory ID: RHSA-2011:0422-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:0422.html Issue date: 2011-04-06 CVE Names: CVE-2008-2937 CVE-2011-0411 ==================================================================== 1. Summary: Updated postfix packages that fix two security issues are now available for Red Hat Enterprise Linux 4 and 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL), and TLS. It was discovered that Postfix did not flush the received SMTP commands buffer after switching to TLS encryption for an SMTP session. A man-in-the-middle attacker could use this flaw to inject SMTP commands into a victim's session during the plain text phase. This would lead to those commands being processed by Postfix after TLS encryption is enabled, possibly allowing the attacker to steal the victim's mail or authentication credentials.(CVE-2011-0411) It was discovered that Postfix did not properly check the permissions of users' mailbox files. A local attacker able to create files in the mail spool directory could use this flaw to create mailbox files for other local users, and be able to read mail delivered to those users. (CVE-2008-2937) Red Hat would like to thank the CERT/CC for reporting CVE-2011-0411, and Sebastian Krahmer of the SuSE Security Team for reporting CVE-2008-2937. The CERT/CC acknowledges Wietse Venema as the original reporter of CVE-2011-0411. Users of Postfix are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. After installing this update, the postfix service will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 456347 - CVE-2008-2937 postfix improper mailbox permissions 674814 - CVE-2011-0411 postfix: SMTP commands injection during plaintext to TLS session switch 6. Package List: Red Hat Enterprise Linux AS version4: Source: i386: postfix-2.2.10-1.4.el4.i386.rpm postfix-debuginfo-2.2.10-1.4.el4.i386.rpm postfix-pflogsumm-2.2.10-1.4.el4.i386.rpm ia64: postfix-2.2.10-1.4.el4.ia64.rpm postfix-debuginfo-2.2.10-1.4.el4.ia64.rpm postfix-pflogsumm-2.2.10-1.4.el4.ia64.rpm ppc: postfix-2.2.10-1.4.el4.ppc.rpm postfix-debuginfo-2.2.10-1.4.el4.ppc.rpm postfix-pflogsumm-2.2.10-1.4.el4.ppc.rpm s390: postfix-2.2.10-1.4.el4.s390.rpm postfix-debuginfo-2.2.10-1.4.el4.s390.rpm postfix-pflogsumm-2.2.10-1.4.el4.s390.rpm s390x: postfix-2.2.10-1.4.el4.s390x.rpm postfix-debuginfo-2.2.10-1.4.el4.s390x.rpm postfix-pflogsumm-2.2.10-1.4.el4.s390x.rpm x86_64: postfix-2.2.10-1.4.el4.x86_64.rpm postfix-debuginfo-2.2.10-1.4.el4.x86_64.rpm postfix-pflogsumm-2.2.10-1.4.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: postfix-2.2.10-1.4.el4.i386.rpm postfix-debuginfo-2.2.10-1.4.el4.i386.rpm postfix-pflogsumm-2.2.10-1.4.el4.i386.rpm x86_64: postfix-2.2.10-1.4.el4.x86_64.rpm postfix-debuginfo-2.2.10-1.4.el4.x86_64.rpm postfix-pflogsumm-2.2.10-1.4.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: postfix-2.2.10-1.4.el4.i386.rpm postfix-debuginfo-2.2.10-1.4.el4.i386.rpm postfix-pflogsumm-2.2.10-1.4.el4.i386.rpm ia64: postfix-2.2.10-1.4.el4.ia64.rpm postfix-debuginfo-2.2.10-1.4.el4.ia64.rpm postfix-pflogsumm-2.2.10-1.4.el4.ia64.rpm x86_64: postfix-2.2.10-1.4.el4.x86_64.rpm postfix-debuginfo-2.2.10-1.4.el4.x86_64.rpm postfix-pflogsumm-2.2.10-1.4.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: postfix-2.2.10-1.4.el4.i386.rpm postfix-debuginfo-2.2.10-1.4.el4.i386.rpm postfix-pflogsumm-2.2.10-1.4.el4.i386.rpm ia64: postfix-2.2.10-1.4.el4.ia64.rpm postfix-debuginfo-2.2.10-1.4.el4.ia64.rpm postfix-pflogsumm-2.2.10-1.4.el4.ia64.rpm x86_64: postfix-2.2.10-1.4.el4.x86_64.rpm postfix-debuginfo-2.2.10-1.4.el4.x86_64.rpm postfix-pflogsumm-2.2.10-1.4.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5client): Source: i386: postfix-2.3.3-2.2.el5_6.i386.rpm postfix-debuginfo-2.3.3-2.2.el5_6.i386.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.i386.rpm x86_64: postfix-2.3.3-2.2.el5_6.x86_64.rpm postfix-debuginfo-2.3.3-2.2.el5_6.x86_64.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: i386: postfix-2.3.3-2.2.el5_6.i386.rpm postfix-debuginfo-2.3.3-2.2.el5_6.i386.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.i386.rpm ia64: postfix-2.3.3-2.2.el5_6.ia64.rpm postfix-debuginfo-2.3.3-2.2.el5_6.ia64.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.ia64.rpm ppc: postfix-2.3.3-2.2.el5_6.ppc.rpm postfix-debuginfo-2.3.3-2.2.el5_6.ppc.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.ppc.rpm s390x: postfix-2.3.3-2.2.el5_6.s390x.rpm postfix-debuginfo-2.3.3-2.2.el5_6.s390x.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.s390x.rpm x86_64: postfix-2.3.3-2.2.el5_6.x86_64.rpm postfix-debuginfo-2.3.3-2.2.el5_6.x86_64.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2008-2937 https://access.redhat.com/security/cve/CVE-2011-0411 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. . Red Hat's recent Postfix update tackles notable security threats. Essential for Linux email functionalities concerning TLS.. Postfix Security, Red Hat Advisory, Mail Transport Agent. . LinuxSecurity.com Team

Calendar%202 Apr 06, 2011 Red Hat
89

Fedora 8: 2023:0011-1 Critical: Postfix Privilege Escalation and DoS

New upstream patch level version 2.5.5, including multiple security fixes detailed in upstream announcements: http://www.postfix.org/announcements/20080814.html http://www.postfix.org/announcements/20080902.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-8595 2008-10-09 04:48:12 --------------------------------------------------------------------------------Name : postfix Product : Fedora 8 Version : 2.5.5 Release : 1.fc8 URL : http://www.postfix.org Summary : Postfix Mail Transport Agent Description : Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL), TLS --------------------------------------------------------------------------------Update Information: New upstream patch level version 2.5.5, including multiple security fixes detailed in upstream announcements: http://www.postfix.org/announcements/20080814.html http://www.postfix.org/announcements/20080902.html --------------------------------------------------------------------------------ChangeLog: * Wed Sep 17 2008 Thomas Woerner 2:2.5.5-1 - new version 2.5.5 fixes CVE-2008-2936, CVE-2008-2937 and CVE-2008-3889 (rhbz#459101) * Thu Aug 28 2008 Tom "spot" Callaway 2:2.5.1-4 - fix license tag * Thu Aug 14 2008 Thomas Woerner 2:2.5.1-3 - fixed postfix privilege problem with symlinks in the mail spool directory (CVE-2008-2936) (rhbz#459101) * Wed Mar 12 2008 Thomas Woerner 2:2.5.1-2 - fixed fix for enabling IPv6 support (rhbz#437024) - added new postfix data directory (rhbz#437042) * Thu Feb 21 2008 Thomas Woerner 2:2.5.1-1 - new verison 2.5.1 * Wed Feb 20 2008 Fedora Release Engineering - 2:2.4.6-3 - Autorebuild for GCC 4.3 * Thu Dec 6 2007 Release Engineering - 2.4.6-2 - Rebuild for deps * Wed Nov 28 2007 Thomas Woerner 2:2.4.6-1 - new verison 2.4.6 - added virtual server(smtp) provide (rhbz#380631) - enabling IPv6 support (rhbz#197105) - made the MYSQL andPGSQL defines overloadable as build argument * Wed Nov 7 2007 Thomas Woerner 2:2.4.5-3 - fixed multilib conflict for makedefs.out: rename to makedefs.out-ppc (rhbz#342941) - enabled mysql support --------------------------------------------------------------------------------References: [ 1 ] Bug #456314 - CVE-2008-2936 postfix privilege escalation flaw https://bugzilla.redhat.com/show_bug.cgi?id=456314 [ 2 ] Bug #456347 - CVE-2008-2937 postfix improper mailbox permissions https://bugzilla.redhat.com/show_bug.cgi?id=456347 [ 3 ] Bug #460906 - CVE-2008-3889 postfix: local DoS via leaked file descriptor https://bugzilla.redhat.com/show_bug.cgi?id=460906 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update postfix' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest update for Fedora 8 Postfix delivers crucial security enhancements. Upgrade to version 2.5.5 to ensure improved safety and system robustness.. Postfix Update, Secure MTA, Fedora 8 Patch, Mail Security, Update Notification. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 09, 2008 Critical Fedora
98

Red Hat: RHSA-2005:025-01 Moderate: Exim Buffer Overflow Exploit Risk

Updated exim packages that resolve security issues are now available for Red Hat Enterprise Linux 4. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: exim security update Advisory ID: RHSA-2005:025-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:025.html Issue date: 2005-02-15 Updated on: 2005-02-15 Product: Red Hat Enterprise Linux CVE Names: CAN-2005-0021 CAN-2005-0022 - ---------------------------------------------------------------------1. Summary: Updated exim packages that resolve security issues are now available for Red Hat Enterprise Linux 4. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: Exim is a mail transport agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet. A buffer overflow was discovered in the spa_base64_to_bits function in Exim, as originally obtained from Samba code. If SPA authentication is enabled, a remote attacker may be able to exploit this vulnerability to execute arbitrary code as the 'exim' user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0022 to this issue. Please note that SPA authentication is not enabled by default in Red Hat Enterprise Linux 4. Buffer overflow flaws were discovered in the host_aton and dns_build_reverse functions in Exim. A local user can trigger these flaws by executing exim with carefullycrafted command line arguments and may be able to gain the privileges of the 'exim' account. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0021 to this issue. Users of Exim are advised to update to these erratum packages which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 144099 - CAN-2005-0021 exim security issues (CAN-2005-0022) 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: a10f8ceafb030dd8de34dfe88479e2fd exim-4.43-1.RHEL4.3.src.rpm i386: 953e48531b0c37fc6f61757fcf7f94ff exim-4.43-1.RHEL4.3.i386.rpm b08043eb300a0c9ba8e7ebf0ec9f5ed9 exim-doc-4.43-1.RHEL4.3.i386.rpm e5489e72dcfd31ab422f43327e7f4a25 exim-mon-4.43-1.RHEL4.3.i386.rpm dd7df7b1937b40edc8e85e3368fa61ab exim-sa-4.43-1.RHEL4.3.i386.rpm ia64: 3ca53a1ee343019a8681c61de01903e4 exim-4.43-1.RHEL4.3.ia64.rpm 5783878bf0fdf7eb62e299b59faa6841 exim-doc-4.43-1.RHEL4.3.ia64.rpm 551864772dc619dae8d8bcdb54eb98c8 exim-mon-4.43-1.RHEL4.3.ia64.rpm a70d6117be6adb454d52996237a6d793 exim-sa-4.43-1.RHEL4.3.ia64.rpm ppc: 839898ae13692a849bc44967d49ca323 exim-4.43-1.RHEL4.3.ppc.rpm 090ee7ef5efb7065f8e28e60c045f174 exim-doc-4.43-1.RHEL4.3.ppc.rpm d14f71166fccc3430b5dc329149ad26b exim-mon-4.43-1.RHEL4.3.ppc.rpm 8e7aedae94f8b35f2020b90e3596d360 exim-sa-4.43-1.RHEL4.3.ppc.rpm s390: fc8c48abd7d386ad9451a1d8467716b8 exim-4.43-1.RHEL4.3.s390.rpm c271ac458a358e66c246046c6d6caf66 exim-doc-4.43-1.RHEL4.3.s390.rpm 6384f141a2c1f720127724586dffa881 exim-mon-4.43-1.RHEL4.3.s390.rpm 6a98adae223421e131e4c656bd21c0da exim-sa-4.43-1.RHEL4.3.s390.rpm s390x: 8c06e65bb46c3ad31dfa140b57184b6d exim-4.43-1.RHEL4.3.s390x.rpm 6f7ebfe85bcd5612ac9e1cedb2b9ffe4 exim-doc-4.43-1.RHEL4.3.s390x.rpm ad1ca1dccbc96f16123a9defc5185e58 exim-mon-4.43-1.RHEL4.3.s390x.rpm 68b146dabe15178ebea73db4ddc16f03 exim-sa-4.43-1.RHEL4.3.s390x.rpm x86_64: 6df49cc0a0e16121f82901f001237f57 exim-4.43-1.RHEL4.3.x86_64.rpm 7f4bed1a8742d92fd4b0b50b6fb00a27 exim-doc-4.43-1.RHEL4.3.x86_64.rpm dfa83c2ee122e616aad216cd040de2f0 exim-mon-4.43-1.RHEL4.3.x86_64.rpm 9e698a46464a5aa565b592e3cdcd5ac2 exim-sa-4.43-1.RHEL4.3.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: a10f8ceafb030dd8de34dfe88479e2fd exim-4.43-1.RHEL4.3.src.rpm i386: 953e48531b0c37fc6f61757fcf7f94ff exim-4.43-1.RHEL4.3.i386.rpm b08043eb300a0c9ba8e7ebf0ec9f5ed9 exim-doc-4.43-1.RHEL4.3.i386.rpm e5489e72dcfd31ab422f43327e7f4a25 exim-mon-4.43-1.RHEL4.3.i386.rpm dd7df7b1937b40edc8e85e3368fa61ab exim-sa-4.43-1.RHEL4.3.i386.rpm x86_64: 6df49cc0a0e16121f82901f001237f57 exim-4.43-1.RHEL4.3.x86_64.rpm 7f4bed1a8742d92fd4b0b50b6fb00a27 exim-doc-4.43-1.RHEL4.3.x86_64.rpm dfa83c2ee122e616aad216cd040de2f0 exim-mon-4.43-1.RHEL4.3.x86_64.rpm 9e698a46464a5aa565b592e3cdcd5ac2 exim-sa-4.43-1.RHEL4.3.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: a10f8ceafb030dd8de34dfe88479e2fd exim-4.43-1.RHEL4.3.src.rpm i386: 953e48531b0c37fc6f61757fcf7f94ff exim-4.43-1.RHEL4.3.i386.rpm b08043eb300a0c9ba8e7ebf0ec9f5ed9 exim-doc-4.43-1.RHEL4.3.i386.rpm e5489e72dcfd31ab422f43327e7f4a25 exim-mon-4.43-1.RHEL4.3.i386.rpm dd7df7b1937b40edc8e85e3368fa61ab exim-sa-4.43-1.RHEL4.3.i386.rpm ia64: 3ca53a1ee343019a8681c61de01903e4 exim-4.43-1.RHEL4.3.ia64.rpm 5783878bf0fdf7eb62e299b59faa6841 exim-doc-4.43-1.RHEL4.3.ia64.rpm 551864772dc619dae8d8bcdb54eb98c8 exim-mon-4.43-1.RHEL4.3.ia64.rpm a70d6117be6adb454d52996237a6d793 exim-sa-4.43-1.RHEL4.3.ia64.rpm x86_64: 6df49cc0a0e16121f82901f001237f57 exim-4.43-1.RHEL4.3.x86_64.rpm 7f4bed1a8742d92fd4b0b50b6fb00a27 exim-doc-4.43-1.RHEL4.3.x86_64.rpm dfa83c2ee122e616aad216cd040de2f0 exim-mon-4.43-1.RHEL4.3.x86_64.rpm 9e698a46464a5aa565b592e3cdcd5ac2 exim-sa-4.43-1.RHEL4.3.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: a10f8ceafb030dd8de34dfe88479e2fd exim-4.43-1.RHEL4.3.src.rpm i386: 953e48531b0c37fc6f61757fcf7f94ff exim-4.43-1.RHEL4.3.i386.rpm b08043eb300a0c9ba8e7ebf0ec9f5ed9 exim-doc-4.43-1.RHEL4.3.i386.rpm e5489e72dcfd31ab422f43327e7f4a25 exim-mon-4.43-1.RHEL4.3.i386.rpm dd7df7b1937b40edc8e85e3368fa61ab exim-sa-4.43-1.RHEL4.3.i386.rpm ia64: 3ca53a1ee343019a8681c61de01903e4 exim-4.43-1.RHEL4.3.ia64.rpm 5783878bf0fdf7eb62e299b59faa6841 exim-doc-4.43-1.RHEL4.3.ia64.rpm 551864772dc619dae8d8bcdb54eb98c8 exim-mon-4.43-1.RHEL4.3.ia64.rpm a70d6117be6adb454d52996237a6d793 exim-sa-4.43-1.RHEL4.3.ia64.rpm x86_64: 6df49cc0a0e16121f82901f001237f57 exim-4.43-1.RHEL4.3.x86_64.rpm 7f4bed1a8742d92fd4b0b50b6fb00a27 exim-doc-4.43-1.RHEL4.3.x86_64.rpm dfa83c2ee122e616aad216cd040de2f0 exim-mon-4.43-1.RHEL4.3.x86_64.rpm 9e698a46464a5aa565b592e3cdcd5ac2 exim-sa-4.43-1.RHEL4.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CAN-2005-0021 https://www.cve.org/CVERecord?id=CAN-2005-0022 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2005 Red Hat, Inc. . Recent updates to Exim packages for Red Hat Enterprise Linux address moderate security vulnerabilities that impact mail transport operations.. Exim Update, Red Hat Advisory, Mail Transport Security. . Severity: Important. LinuxSecurity.comTeam

Calendar%202 Feb 15, 2005 Important Red Hat
87

Debian: DSA 376-1 Critical: Exim Buffer Overflow Threat

A buffer overflow exists in exim, which is the standard mail transportagent in Debian. By supplying a specially crafted HELO or EHLOcommand, an attacker could cause a constant string to be written pastthe end of a buffer allocated on the heap. This vulnerability is notbelieved at this time to be exploitable to execute arbitrary code.. -------------------------------------------------------------------------- Debian Security Advisory DSA 376-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Matt Zimmerman September 4th, 2003 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : exim exim-tls Vulnerability : buffer overflow Problem-Type : remote Debian-specific: no CVE Ids : CAN-2003-0743 A buffer overflow exists in exim, which is the standard mail transport agent in Debian. By supplying a specially crafted HELO or EHLO command, an attacker could cause a constant string to be written past the end of a buffer allocated on the heap. This vulnerability is not believed at this time to be exploitable to execute arbitrary code. For the stable distribution (woody) this problem has been fixed in exim version 3.35-1woody1 and exim-tls version 3.35-3woody1. For the unstable distribution (sid) this problem has been fixed in exim version 3.36-8. The unstable distribution does not contain an exim-tls package. We recommend that you update your exim or exim-tls package. Upgrade Instructions -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 aliaswoody -------------------------------- Source archives: Size/MD5 checksum: 661 34a7faf2980c66aab318512a36a2c656 Size/MD5 checksum: 79296 0839fd89bd648ee5828e55afe6ce3628 Size/MD5 checksum: 1271057 42d362e40a21bd7ffc298f92c8bd986a Size/MD5 checksum: 677 efc414eda2eaf3b739c0ff1d0ce1ce08 Size/MD5 checksum: 79663 3b0ffcb9a0c4662ba908f622e6bc6923 Size/MD5 checksum: 1271057 42d362e40a21bd7ffc298f92c8bd986a Alpha architecture: Size/MD5 checksum: 872528 0c6303e4ab06e4aef0b65e8be9dd6dea Size/MD5 checksum: 52316 ebc1ae6e92ebd810a4ffd3f7369995f9 Size/MD5 checksum: 873212 19bba89ff92748d38fc68a667474ed35 ARM architecture: Size/MD5 checksum: 785544 2bd24816a3290cdaa2bdcd52893f738c Size/MD5 checksum: 43522 d368467b3e01b7525b06d810ddee91de Size/MD5 checksum: 783822 4a14319839d9f01dd2be37e047fd6d66 Intel IA-32 architecture: Size/MD5 checksum: 758810 d562e8c0093c8fd1eac2a4b6756b2c74 Size/MD5 checksum: 39204 eb5b733cbab82e3613368b117c7ccba8 Size/MD5 checksum: 759152 ad293a317eb4ee7bccffff05a425156e Intel IA-64 architecture: Size/MD5 checksum: 972460 490ba5d8e041b14de7bab91d25cd8e84 Size/MD5 checksum: 65172 151a1cac77506fe862a1d7bd6e800ef4 Size/MD5 checksum: 973764 ee164461e235691d1ebbd5499535bb23 HP Precision architecture: Size/MD5 checksum: 814904 e6865edc611c89d9846aabb61fd0a8f6 Size/MD5 checksum: 48278 d0a74247177785fc79511b03e855c247 Size/MD5 checksum: 813986 5b98643ddca3a563c0f35702533abec7 Motorola 680x0 architecture: Size/MD5 checksum: 737612 cdc5648c0a2f0785d9a31f8bed6225cc Size/MD5 checksum: 37762 138c8847fc4586c4fbabe0358427b752 Size/MD5 checksum: 736502 387d9a32b505ec7f3e8cedad5390095a Big endian MIPS architecture: Size/MD5 checksum: 824132 16515eef87fbea27dd0269bbfd82b804 Size/MD5 checksum: 48868 b54faf31be830fc6d88ca91fd92aec15 Size/MD5 checksum: 824072 068d46cc7be1f70e369795eed39a5e2c Little endian MIPS architecture: Size/MD5 checksum: 824350 1e4beb825601c1d6034ed1236a1ddae0 Size/MD5 checksum: 48770 ae84a1825f88b5e12ed94a4050bac66c Size/MD5 checksum: 824764 dc94f41f414b487a5fb242abf1691c71 PowerPC architecture: Size/MD5 checksum: 793734 8751038ff5bc501e701568180cf918df Size/MD5 checksum: 44782 a295cd17f3d6f97d5f41a149c4aafe76 Size/MD5 checksum: 792296 a8e7e8d5c05ad550d02ebed47ec98ee8 IBM S/390 architecture: Size/MD5 checksum: 779618 0f914e0637333149eac25dfb72e1626a Size/MD5 checksum: 43928 f88d92626105590087361b2d8042c3f7 Size/MD5 checksum: 778952 a1f2ada573819be4637929c3763a6193 Sun Sparc architecture: Size/MD5 checksum: 784920 0309da1ad933034ebcec4c44e6bad64a Size/MD5 checksum: 42440 d26369a10e324da946baa8d17f401c1c Size/MD5 checksum: 782482 4ae58125f8e4daea23660df37e867c14 These files will probably be moved into the stable distribution on its next revision. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Critical buffer overflow in Exim for Debian requires urgent updates to maintain security and prevent potential exploits.. debian, exim, buffer overflow, mail transport. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 05, 2003 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200