CVE-2019-15846: Exim - local or remote attacker can execute programs with root privileges.

Heiko Schlittermann via Exim-announce <[email protected]> Wed, 4 Sep 2019 11:22:48 +0200
Newsgroups gmane.mail.exim.announce
Organization schlittermann -- internet & unix support
Message-ID <20190904092248.GQ3837__31679.1020029754$1567590229$gmane$org@jumper.schlittermann.de>
--===============1786052871==
Content-Type: multipart/signed; micalg=pgp-sha512;
	protocol="application/pgp-signature"; boundary="PEfPc/DjvCj+JzNg"
Content-Disposition: inline


--PEfPc/DjvCj+JzNg
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

*** Note: EMBARGO is still in effect!       ***
*** Distros must not publish any detail yet ***

Head up! Security release ahead!

CVE ID:     CVE-2019-15846
Version(s): up to and including 4.92.1
Issue:      A local or remote attacker can execute programs with root
            privileges.
Details:    Will be made public at CRD. Currently there is no known
            exploit, but a rudimentary POC exists.

Coordinated Release Date (CRD) for Exim 4.92.2:
            2019-09-06 10:00 UTC

Contact:    [email protected]

Proposed Timeline
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

2019-09-03:
    - initial notification to [email protected] and
      [email protected]

2019-09-04: <-- NOW
    - This Heads-up notice to [email protected],
      [email protected], and [email protected]

2019-09-06 10:00 UTC:
    - Coordinated relase date
    - Notice to oss-security, exim-users, and exim-announce
    - Publish the patches in our official and public Git repositories
      and the packages on our FTP server.

Downloads available starting at CRD (not yet)
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

The downloads are not yet available. They will be made available
at the above mentioned CRD.

Release tarballs (exim-4.92.2):

    https://ftp.exim.org/pub/exim/exim4/

The package files are signed with my GPG key.

The full Git repo:

    https://git.exim.org/exim.git
    https://github.com/Exim/exim    [mirror of the above]
    - tag    exim-4.92.2
    - branch exim-4.92.2+fixes

The tagged commit is the officially released version. The tag is signed
with my GPG key.  The +fixes branch isn't officially maintained, but
contains useful patches *and* the security fix. The relevant commit is
signed with my GPG key. The old exim-4.92.1+fixes branch is being functiona=
lly
replaced by the new exim-4.92.2+fixes branch.

    Best regards from Dresden/Germany
    Viele Gr=C3=BC=C3=9Fe aus Dresden
    Heiko Schlittermann
--
 SCHLITTERMANN.de ---------------------------- internet & unix support -
 Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
 gnupg encrypted messages are welcome --------------- key ID: F69376CE -
 ! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -

--PEfPc/DjvCj+JzNg
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAABCgAdFiEE0L/WueylaUpvFJ3Or0zGdqa2wUIFAl1vgmgACgkQr0zGdqa2
wULCmQf8COw+yp2fYQ7ZNNvkHhGFiQ9FPtURDLJ/Ysg3HpkcZxxAXRfB6IRfaE1W
N3yS8YN781m+uCEiNCztEwgAULLouOQWy4asKa7K40cMphW+tJT3TQtsllqp/NtT
5SE+Tht68GsjJt1iWiw+OPbEljRnx4wyCT7MLKWFgBinGCr/jN2jNLuJ7zkrZToW
MjzOFHUgOT9kGo4UvbcdbGJ6mV4hV3uScVOaEfK0v3OEnO+4RJvB2e5Pt10SijFl
ZINAizEKP5KhMnjSSgErlwVjeUfS1RXCDf7hbwV10qRalWtL6GdAJqOv6aRXiPJS
SHkc0MfzudJZmMXEHRxt9HlRQMT2gQ==
=kfZm
-----END PGP SIGNATURE-----

--PEfPc/DjvCj+JzNg--


--===============1786052871==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
## List details at https://lists.exim.org/mailman/listinfo/exim-announce Exim details at http://www.exim.org/ ##

--===============1786052871==--