Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Multiple potential security vulnerabilities have been addressed in exim4, a mail transport agent. These issues may allow remote attackers to disclose sensitive information or execute arbitrary code but only if Exim4 is run behind or with untrusted proxy servers or DNS resolvers. If your proxy-protocol proxy . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3938-1
It was discovered that Exim, a mail transport agent, can be induced to accept a second message embedded as part of the body of a first message in certain configurations where PIPELINING or CHUNKING on incoming connections is offered. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5597-1
Several security issues were fixed in Exim.. =========================================================================Ubuntu Security Notice USN-4934-2 May 06, 2021 exim4 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Several security issues were fixed in Exim. Software Description: - exim4: Exim is a mail transport agent Details: USN-4934-1 fixed several vulnerabilities in Exim. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. CVE-2020-28026 only affected Ubuntu 16.04 ESM. Original advisory details: It was discovered that Exim contained multiple security issues. An attacker could use these issues to cause a denial of service, execute arbitrary code remotely, obtain sensitive information, or escalate local privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: exim4-base 4.86.2-2ubuntu2.6+esm1 exim4-daemon-heavy 4.86.2-2ubuntu2.6+esm1 exim4-daemon-light 4.86.2-2ubuntu2.6+esm1 Ubuntu 14.04 ESM: exim4-base 4.82-3ubuntu2.4+esm3 exim4-daemon-heavy 4.82-3ubuntu2.4+esm3 exim4-daemon-light 4.82-3ubuntu2.4+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4934-2 https://ubuntu.com/security/notices/USN-4934-1 CVE-2020-28007, CVE-2020-28008, CVE-2020-28009, CVE-2020-28011, CVE-2020-28012, CVE-2020-28013, CVE-2020-28014, CVE-2020-28015, CVE-2020-28016, CVE-2020-28017, CVE-2020-28020, CVE-2020-28022, CVE-2020-28024, CVE-2020-28025, CVE-2020-28026, CVE-2021-27216 . Multiple security issues in Exim addressed by Ubuntu advisory 4934-2, impacting versions 14.04 and 16.04 ESM.. Exim Fix, Denial Of Service, Ubuntu Security Notice. .Severity: Critical. LinuxSecurity.com Team
Updated postfix packages that fix two security issues are now available for Red Hat Enterprise Linux 4 and 5. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: postfix security update Advisory ID: RHSA-2011:0422-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:0422.html Issue date: 2011-04-06 CVE Names: CVE-2008-2937 CVE-2011-0411 ==================================================================== 1. Summary: Updated postfix packages that fix two security issues are now available for Red Hat Enterprise Linux 4 and 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL), and TLS. It was discovered that Postfix did not flush the received SMTP commands buffer after switching to TLS encryption for an SMTP session. A man-in-the-middle attacker could use this flaw to inject SMTP commands into a victim's session during the plain text phase. This would lead to those commands being processed by Postfix after TLS encryption is enabled, possibly allowing the attacker to steal the victim's mail or authentication credentials.(CVE-2011-0411) It was discovered that Postfix did not properly check the permissions of users' mailbox files. A local attacker able to create files in the mail spool directory could use this flaw to create mailbox files for other local users, and be able to read mail delivered to those users. (CVE-2008-2937) Red Hat would like to thank the CERT/CC for reporting CVE-2011-0411, and Sebastian Krahmer of the SuSE Security Team for reporting CVE-2008-2937. The CERT/CC acknowledges Wietse Venema as the original reporter of CVE-2011-0411. Users of Postfix are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. After installing this update, the postfix service will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 456347 - CVE-2008-2937 postfix improper mailbox permissions 674814 - CVE-2011-0411 postfix: SMTP commands injection during plaintext to TLS session switch 6. Package List: Red Hat Enterprise Linux AS version4: Source: i386: postfix-2.2.10-1.4.el4.i386.rpm postfix-debuginfo-2.2.10-1.4.el4.i386.rpm postfix-pflogsumm-2.2.10-1.4.el4.i386.rpm ia64: postfix-2.2.10-1.4.el4.ia64.rpm postfix-debuginfo-2.2.10-1.4.el4.ia64.rpm postfix-pflogsumm-2.2.10-1.4.el4.ia64.rpm ppc: postfix-2.2.10-1.4.el4.ppc.rpm postfix-debuginfo-2.2.10-1.4.el4.ppc.rpm postfix-pflogsumm-2.2.10-1.4.el4.ppc.rpm s390: postfix-2.2.10-1.4.el4.s390.rpm postfix-debuginfo-2.2.10-1.4.el4.s390.rpm postfix-pflogsumm-2.2.10-1.4.el4.s390.rpm s390x: postfix-2.2.10-1.4.el4.s390x.rpm postfix-debuginfo-2.2.10-1.4.el4.s390x.rpm postfix-pflogsumm-2.2.10-1.4.el4.s390x.rpm x86_64: postfix-2.2.10-1.4.el4.x86_64.rpm postfix-debuginfo-2.2.10-1.4.el4.x86_64.rpm postfix-pflogsumm-2.2.10-1.4.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: postfix-2.2.10-1.4.el4.i386.rpm postfix-debuginfo-2.2.10-1.4.el4.i386.rpm postfix-pflogsumm-2.2.10-1.4.el4.i386.rpm x86_64: postfix-2.2.10-1.4.el4.x86_64.rpm postfix-debuginfo-2.2.10-1.4.el4.x86_64.rpm postfix-pflogsumm-2.2.10-1.4.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: postfix-2.2.10-1.4.el4.i386.rpm postfix-debuginfo-2.2.10-1.4.el4.i386.rpm postfix-pflogsumm-2.2.10-1.4.el4.i386.rpm ia64: postfix-2.2.10-1.4.el4.ia64.rpm postfix-debuginfo-2.2.10-1.4.el4.ia64.rpm postfix-pflogsumm-2.2.10-1.4.el4.ia64.rpm x86_64: postfix-2.2.10-1.4.el4.x86_64.rpm postfix-debuginfo-2.2.10-1.4.el4.x86_64.rpm postfix-pflogsumm-2.2.10-1.4.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: postfix-2.2.10-1.4.el4.i386.rpm postfix-debuginfo-2.2.10-1.4.el4.i386.rpm postfix-pflogsumm-2.2.10-1.4.el4.i386.rpm ia64: postfix-2.2.10-1.4.el4.ia64.rpm postfix-debuginfo-2.2.10-1.4.el4.ia64.rpm postfix-pflogsumm-2.2.10-1.4.el4.ia64.rpm x86_64: postfix-2.2.10-1.4.el4.x86_64.rpm postfix-debuginfo-2.2.10-1.4.el4.x86_64.rpm postfix-pflogsumm-2.2.10-1.4.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5client): Source: i386: postfix-2.3.3-2.2.el5_6.i386.rpm postfix-debuginfo-2.3.3-2.2.el5_6.i386.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.i386.rpm x86_64: postfix-2.3.3-2.2.el5_6.x86_64.rpm postfix-debuginfo-2.3.3-2.2.el5_6.x86_64.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: i386: postfix-2.3.3-2.2.el5_6.i386.rpm postfix-debuginfo-2.3.3-2.2.el5_6.i386.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.i386.rpm ia64: postfix-2.3.3-2.2.el5_6.ia64.rpm postfix-debuginfo-2.3.3-2.2.el5_6.ia64.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.ia64.rpm ppc: postfix-2.3.3-2.2.el5_6.ppc.rpm postfix-debuginfo-2.3.3-2.2.el5_6.ppc.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.ppc.rpm s390x: postfix-2.3.3-2.2.el5_6.s390x.rpm postfix-debuginfo-2.3.3-2.2.el5_6.s390x.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.s390x.rpm x86_64: postfix-2.3.3-2.2.el5_6.x86_64.rpm postfix-debuginfo-2.3.3-2.2.el5_6.x86_64.rpm postfix-pflogsumm-2.3.3-2.2.el5_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2008-2937 https://access.redhat.com/security/cve/CVE-2011-0411 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. . Red Hat's recent Postfix update tackles notable security threats. Essential for Linux email functionalities concerning TLS.. Postfix Security, Red Hat Advisory, Mail Transport Agent. . LinuxSecurity.com Team
New upstream patch level version 2.5.5, including multiple security fixes detailed in upstream announcements: http://www.postfix.org/announcements/20080814.html http://www.postfix.org/announcements/20080902.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-8595 2008-10-09 04:48:12 --------------------------------------------------------------------------------Name : postfix Product : Fedora 8 Version : 2.5.5 Release : 1.fc8 URL : http://www.postfix.org Summary : Postfix Mail Transport Agent Description : Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL), TLS --------------------------------------------------------------------------------Update Information: New upstream patch level version 2.5.5, including multiple security fixes detailed in upstream announcements: http://www.postfix.org/announcements/20080814.html http://www.postfix.org/announcements/20080902.html --------------------------------------------------------------------------------ChangeLog: * Wed Sep 17 2008 Thomas Woerner 2:2.5.5-1 - new version 2.5.5 fixes CVE-2008-2936, CVE-2008-2937 and CVE-2008-3889 (rhbz#459101) * Thu Aug 28 2008 Tom "spot" Callaway 2:2.5.1-4 - fix license tag * Thu Aug 14 2008 Thomas Woerner 2:2.5.1-3 - fixed postfix privilege problem with symlinks in the mail spool directory (CVE-2008-2936) (rhbz#459101) * Wed Mar 12 2008 Thomas Woerner 2:2.5.1-2 - fixed fix for enabling IPv6 support (rhbz#437024) - added new postfix data directory (rhbz#437042) * Thu Feb 21 2008 Thomas Woerner 2:2.5.1-1 - new verison 2.5.1 * Wed Feb 20 2008 Fedora Release Engineering - 2:2.4.6-3 - Autorebuild for GCC 4.3 * Thu Dec 6 2007 Release Engineering - 2.4.6-2 - Rebuild for deps * Wed Nov 28 2007 Thomas Woerner 2:2.4.6-1 - new verison 2.4.6 - added virtual server(smtp) provide (rhbz#380631) - enabling IPv6 support (rhbz#197105) - made the MYSQL andPGSQL defines overloadable as build argument * Wed Nov 7 2007 Thomas Woerner 2:2.4.5-3 - fixed multilib conflict for makedefs.out: rename to makedefs.out-ppc (rhbz#342941) - enabled mysql support --------------------------------------------------------------------------------References: [ 1 ] Bug #456314 - CVE-2008-2936 postfix privilege escalation flaw https://bugzilla.redhat.com/show_bug.cgi?id=456314 [ 2 ] Bug #456347 - CVE-2008-2937 postfix improper mailbox permissions https://bugzilla.redhat.com/show_bug.cgi?id=456347 [ 3 ] Bug #460906 - CVE-2008-3889 postfix: local DoS via leaked file descriptor https://bugzilla.redhat.com/show_bug.cgi?id=460906 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update postfix' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Updated exim packages that resolve security issues are now available for Red Hat Enterprise Linux 4. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: exim security update Advisory ID: RHSA-2005:025-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:025.html Issue date: 2005-02-15 Updated on: 2005-02-15 Product: Red Hat Enterprise Linux CVE Names: CAN-2005-0021 CAN-2005-0022 - ---------------------------------------------------------------------1. Summary: Updated exim packages that resolve security issues are now available for Red Hat Enterprise Linux 4. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: Exim is a mail transport agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet. A buffer overflow was discovered in the spa_base64_to_bits function in Exim, as originally obtained from Samba code. If SPA authentication is enabled, a remote attacker may be able to exploit this vulnerability to execute arbitrary code as the 'exim' user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0022 to this issue. Please note that SPA authentication is not enabled by default in Red Hat Enterprise Linux 4. Buffer overflow flaws were discovered in the host_aton and dns_build_reverse functions in Exim. A local user can trigger these flaws by executing exim with carefullycrafted command line arguments and may be able to gain the privileges of the 'exim' account. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0021 to this issue. Users of Exim are advised to update to these erratum packages which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 144099 - CAN-2005-0021 exim security issues (CAN-2005-0022) 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: a10f8ceafb030dd8de34dfe88479e2fd exim-4.43-1.RHEL4.3.src.rpm i386: 953e48531b0c37fc6f61757fcf7f94ff exim-4.43-1.RHEL4.3.i386.rpm b08043eb300a0c9ba8e7ebf0ec9f5ed9 exim-doc-4.43-1.RHEL4.3.i386.rpm e5489e72dcfd31ab422f43327e7f4a25 exim-mon-4.43-1.RHEL4.3.i386.rpm dd7df7b1937b40edc8e85e3368fa61ab exim-sa-4.43-1.RHEL4.3.i386.rpm ia64: 3ca53a1ee343019a8681c61de01903e4 exim-4.43-1.RHEL4.3.ia64.rpm 5783878bf0fdf7eb62e299b59faa6841 exim-doc-4.43-1.RHEL4.3.ia64.rpm 551864772dc619dae8d8bcdb54eb98c8 exim-mon-4.43-1.RHEL4.3.ia64.rpm a70d6117be6adb454d52996237a6d793 exim-sa-4.43-1.RHEL4.3.ia64.rpm ppc: 839898ae13692a849bc44967d49ca323 exim-4.43-1.RHEL4.3.ppc.rpm 090ee7ef5efb7065f8e28e60c045f174 exim-doc-4.43-1.RHEL4.3.ppc.rpm d14f71166fccc3430b5dc329149ad26b exim-mon-4.43-1.RHEL4.3.ppc.rpm 8e7aedae94f8b35f2020b90e3596d360 exim-sa-4.43-1.RHEL4.3.ppc.rpm s390: fc8c48abd7d386ad9451a1d8467716b8 exim-4.43-1.RHEL4.3.s390.rpm c271ac458a358e66c246046c6d6caf66 exim-doc-4.43-1.RHEL4.3.s390.rpm 6384f141a2c1f720127724586dffa881 exim-mon-4.43-1.RHEL4.3.s390.rpm 6a98adae223421e131e4c656bd21c0da exim-sa-4.43-1.RHEL4.3.s390.rpm s390x: 8c06e65bb46c3ad31dfa140b57184b6d exim-4.43-1.RHEL4.3.s390x.rpm 6f7ebfe85bcd5612ac9e1cedb2b9ffe4 exim-doc-4.43-1.RHEL4.3.s390x.rpm ad1ca1dccbc96f16123a9defc5185e58 exim-mon-4.43-1.RHEL4.3.s390x.rpm 68b146dabe15178ebea73db4ddc16f03 exim-sa-4.43-1.RHEL4.3.s390x.rpm x86_64: 6df49cc0a0e16121f82901f001237f57 exim-4.43-1.RHEL4.3.x86_64.rpm 7f4bed1a8742d92fd4b0b50b6fb00a27 exim-doc-4.43-1.RHEL4.3.x86_64.rpm dfa83c2ee122e616aad216cd040de2f0 exim-mon-4.43-1.RHEL4.3.x86_64.rpm 9e698a46464a5aa565b592e3cdcd5ac2 exim-sa-4.43-1.RHEL4.3.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: a10f8ceafb030dd8de34dfe88479e2fd exim-4.43-1.RHEL4.3.src.rpm i386: 953e48531b0c37fc6f61757fcf7f94ff exim-4.43-1.RHEL4.3.i386.rpm b08043eb300a0c9ba8e7ebf0ec9f5ed9 exim-doc-4.43-1.RHEL4.3.i386.rpm e5489e72dcfd31ab422f43327e7f4a25 exim-mon-4.43-1.RHEL4.3.i386.rpm dd7df7b1937b40edc8e85e3368fa61ab exim-sa-4.43-1.RHEL4.3.i386.rpm x86_64: 6df49cc0a0e16121f82901f001237f57 exim-4.43-1.RHEL4.3.x86_64.rpm 7f4bed1a8742d92fd4b0b50b6fb00a27 exim-doc-4.43-1.RHEL4.3.x86_64.rpm dfa83c2ee122e616aad216cd040de2f0 exim-mon-4.43-1.RHEL4.3.x86_64.rpm 9e698a46464a5aa565b592e3cdcd5ac2 exim-sa-4.43-1.RHEL4.3.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: a10f8ceafb030dd8de34dfe88479e2fd exim-4.43-1.RHEL4.3.src.rpm i386: 953e48531b0c37fc6f61757fcf7f94ff exim-4.43-1.RHEL4.3.i386.rpm b08043eb300a0c9ba8e7ebf0ec9f5ed9 exim-doc-4.43-1.RHEL4.3.i386.rpm e5489e72dcfd31ab422f43327e7f4a25 exim-mon-4.43-1.RHEL4.3.i386.rpm dd7df7b1937b40edc8e85e3368fa61ab exim-sa-4.43-1.RHEL4.3.i386.rpm ia64: 3ca53a1ee343019a8681c61de01903e4 exim-4.43-1.RHEL4.3.ia64.rpm 5783878bf0fdf7eb62e299b59faa6841 exim-doc-4.43-1.RHEL4.3.ia64.rpm 551864772dc619dae8d8bcdb54eb98c8 exim-mon-4.43-1.RHEL4.3.ia64.rpm a70d6117be6adb454d52996237a6d793 exim-sa-4.43-1.RHEL4.3.ia64.rpm x86_64: 6df49cc0a0e16121f82901f001237f57 exim-4.43-1.RHEL4.3.x86_64.rpm 7f4bed1a8742d92fd4b0b50b6fb00a27 exim-doc-4.43-1.RHEL4.3.x86_64.rpm dfa83c2ee122e616aad216cd040de2f0 exim-mon-4.43-1.RHEL4.3.x86_64.rpm 9e698a46464a5aa565b592e3cdcd5ac2 exim-sa-4.43-1.RHEL4.3.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: a10f8ceafb030dd8de34dfe88479e2fd exim-4.43-1.RHEL4.3.src.rpm i386: 953e48531b0c37fc6f61757fcf7f94ff exim-4.43-1.RHEL4.3.i386.rpm b08043eb300a0c9ba8e7ebf0ec9f5ed9 exim-doc-4.43-1.RHEL4.3.i386.rpm e5489e72dcfd31ab422f43327e7f4a25 exim-mon-4.43-1.RHEL4.3.i386.rpm dd7df7b1937b40edc8e85e3368fa61ab exim-sa-4.43-1.RHEL4.3.i386.rpm ia64: 3ca53a1ee343019a8681c61de01903e4 exim-4.43-1.RHEL4.3.ia64.rpm 5783878bf0fdf7eb62e299b59faa6841 exim-doc-4.43-1.RHEL4.3.ia64.rpm 551864772dc619dae8d8bcdb54eb98c8 exim-mon-4.43-1.RHEL4.3.ia64.rpm a70d6117be6adb454d52996237a6d793 exim-sa-4.43-1.RHEL4.3.ia64.rpm x86_64: 6df49cc0a0e16121f82901f001237f57 exim-4.43-1.RHEL4.3.x86_64.rpm 7f4bed1a8742d92fd4b0b50b6fb00a27 exim-doc-4.43-1.RHEL4.3.x86_64.rpm dfa83c2ee122e616aad216cd040de2f0 exim-mon-4.43-1.RHEL4.3.x86_64.rpm 9e698a46464a5aa565b592e3cdcd5ac2 exim-sa-4.43-1.RHEL4.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CAN-2005-0021 https://www.cve.org/CVERecord?id=CAN-2005-0022 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2005 Red Hat, Inc. . Recent updates to Exim packages for Red Hat Enterprise Linux address moderate security vulnerabilities that impact mail transport operations.. Exim Update, Red Hat Advisory, Mail Transport Security. . Severity: Important. LinuxSecurity.comTeam
A buffer overflow exists in exim, which is the standard mail transportagent in Debian. By supplying a specially crafted HELO or EHLOcommand, an attacker could cause a constant string to be written pastthe end of a buffer allocated on the heap. This vulnerability is notbelieved at this time to be exploitable to execute arbitrary code.. -------------------------------------------------------------------------- Debian Security Advisory DSA 376-1
Get the latest Linux and open source security news straight to your inbox.