Re: [BLFS Trac] #23224: exim-4.99.3 (was: exim-4.99.2)
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23224: exim-4.99.3
-------------------------+------------------------------
Reporter: Bruce Dubbs | Owner: Douglas R. Reno
Type: enhancement | Status: assigned
Priority: elevated | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+------------------------------
Changes (by Douglas R. Reno):
* summary: exim-4.99.2 => exim-4.99.3
Comment:
Now 4.99.3:
{{{
Hello,
The Exim maintainers are releasing an important security update to address
a critical vulnerability affecting certain Exim configurations.
Vulnerability Details
A remotely reachable Use-After-Free (UAF) vulnerability has been
identified in Exim's BDAT (binary data transmission) body parsing path
when using the GnuTLS backend. This vulnerability can lead to heap
corruption and potential code execution.
Affected Versions and Configurations
This vulnerability affects Exim versions 4.97 through 4.99.x that:
- Are built with GnuTLS support
- Have STARTTLS and CHUNKING advertised
Recommended Action
We strongly recommend all affected users upgrade to Exim 4.99.3 or later
immediately.
Obtaining the Fix
Fixed versions are available:
- Repository: https://code.exim.org/exim-/exim (branch: exim-4.99+fixes,
tag: exim-4.99.3) (signed by me)
- Tarballs: https://downloads.exim.org/exim4/ (signed by me)
- Please see the Exim website for detailed upgrade instructions
Additional Information
- Distros already have coordinated access to patches
- Internal tracking ID: EXIM-Security-2026-05-01.1
- Full technical details will be available:
https://exim.org/static/doc/security/EXIM-Security-2026-05-01.1/
}}}
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23224#comment:2>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page