[Git][security-tracker-team/security-tracker][master] add exim4 commit references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Apr 30 10:34:58 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e79e8c91 by Moritz Muehlenhoff at 2026-04-30T11:34:16+02:00
add exim4 commit references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -261,13 +261,18 @@ CVE-2026-7381 (Plack::Middleware::XSendfile versions through 1.0053 for Perl can
- libplack-perl <unfixed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/39467666/
CVE-2026-40684 [Possible crash with malicious DNS data when using musl libc]
- - exim4 4.99.2-1
+ - exim4 4.99.2-1 (unimportant)
+ NOTE: Fixed by: https://code.exim.org/exim/exim/commit/628bbaca7672748d941a12e7cd5f0122a4e18c81
+ NOTE: Debian builds with glibc
CVE-2026-40685 [Possible OOB read/write on corrupt JSON in header]
- exim4 4.99.2-1
+ NOTE: Fixed by: https://code.exim.org/exim/exim/commit/9fdc057e71b87c87a0d3d2288b2810a0efaaba57
CVE-2026-40686 [Possible OOB read with large UTF8 trailing characters]
- exim4 4.99.2-1
+ NOTE: Fixed by: https://code.exim.org/exim/exim/commit/f2570bde16fb4d4a1242ff363a4c4eecf6372efc
CVE-2026-40687 [Possible OOB read/write with SPA authenticator]
- exim4 4.99.2-1
+ NOTE: Fixed by: https://code.exim.org/exim/exim/commit/68b963b9f75ca27b38e1c0f8c87037990199f505
CVE-2026-7466 (AgentFlow contains an arbitrary code execution vulnerability that allo ...)
NOT-FOR-US: AgentFlow
CVE-2026-7439 (AgentFlow's local web API accepts non-JSON content types on POST /api/ ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e79e8c910cc3482b48f2c855629dc4296d9c8b73
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e79e8c910cc3482b48f2c855629dc4296d9c8b73
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260430/6cf56f88/attachment.htm>
More information about the debian-security-tracker-commits
mailing list