CVE-2019-15846: Exim - local or remote attacker can execute programs with root privileges.
Heiko Schlittermann via Exim-announce <[email protected]> Wed, 4 Sep 2019 11:22:48 +0200
| Newsgroups | gmane.mail.exim.announce |
|---|---|
| Organization | schlittermann -- internet & unix support |
| Message-ID | <20190904092248.GQ3837__31679.1020029754$1567590229$gmane$org@jumper.schlittermann.de> |
--===============1786052871==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature"; boundary="PEfPc/DjvCj+JzNg"
Content-Disposition: inline
--PEfPc/DjvCj+JzNg
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
*** Note: EMBARGO is still in effect! ***
*** Distros must not publish any detail yet ***
Head up! Security release ahead!
CVE ID: CVE-2019-15846
Version(s): up to and including 4.92.1
Issue: A local or remote attacker can execute programs with root
privileges.
Details: Will be made public at CRD. Currently there is no known
exploit, but a rudimentary POC exists.
Coordinated Release Date (CRD) for Exim 4.92.2:
2019-09-06 10:00 UTC
Contact: [email protected]
Proposed Timeline
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
2019-09-03:
- initial notification to [email protected] and
[email protected]
2019-09-04: <-- NOW
- This Heads-up notice to [email protected],
[email protected], and [email protected]
2019-09-06 10:00 UTC:
- Coordinated relase date
- Notice to oss-security, exim-users, and exim-announce
- Publish the patches in our official and public Git repositories
and the packages on our FTP server.
Downloads available starting at CRD (not yet)
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
The downloads are not yet available. They will be made available
at the above mentioned CRD.
Release tarballs (exim-4.92.2):
https://ftp.exim.org/pub/exim/exim4/
The package files are signed with my GPG key.
The full Git repo:
https://git.exim.org/exim.git
https://github.com/Exim/exim [mirror of the above]
- tag exim-4.92.2
- branch exim-4.92.2+fixes
The tagged commit is the officially released version. The tag is signed
with my GPG key. The +fixes branch isn't officially maintained, but
contains useful patches *and* the security fix. The relevant commit is
signed with my GPG key. The old exim-4.92.1+fixes branch is being functiona=
lly
replaced by the new exim-4.92.2+fixes branch.
Best regards from Dresden/Germany
Viele Gr=C3=BC=C3=9Fe aus Dresden
Heiko Schlittermann
--
SCHLITTERMANN.de ---------------------------- internet & unix support -
Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
gnupg encrypted messages are welcome --------------- key ID: F69376CE -
! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -
--PEfPc/DjvCj+JzNg
Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQEzBAABCgAdFiEE0L/WueylaUpvFJ3Or0zGdqa2wUIFAl1vgmgACgkQr0zGdqa2
wULCmQf8COw+yp2fYQ7ZNNvkHhGFiQ9FPtURDLJ/Ysg3HpkcZxxAXRfB6IRfaE1W
N3yS8YN781m+uCEiNCztEwgAULLouOQWy4asKa7K40cMphW+tJT3TQtsllqp/NtT
5SE+Tht68GsjJt1iWiw+OPbEljRnx4wyCT7MLKWFgBinGCr/jN2jNLuJ7zkrZToW
MjzOFHUgOT9kGo4UvbcdbGJ6mV4hV3uScVOaEfK0v3OEnO+4RJvB2e5Pt10SijFl
ZINAizEKP5KhMnjSSgErlwVjeUfS1RXCDf7hbwV10qRalWtL6GdAJqOv6aRXiPJS
SHkc0MfzudJZmMXEHRxt9HlRQMT2gQ==
=kfZm
-----END PGP SIGNATURE-----
--PEfPc/DjvCj+JzNg--
--===============1786052871==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--
## List details at https://lists.exim.org/mailman/listinfo/exim-announce Exim details at http://www.exim.org/ ##
--===============1786052871==--