exim4_4.92-8+deb10u6_multi.changes ACCEPTED into proposed-updates->stable-new, proposed-updates
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Fri May 7 16:17:06 BST 2021
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 01 May 2021 11:42:39 +0200
Source: exim4
Architecture: source
Version: 4.92-8+deb10u6
Distribution: buster-security
Urgency: high
Maintainer: Exim4 Maintainers <pkg-exim4-maintainers at lists.alioth.debian.org>
Changed-By: Andreas Metzler <ametzler at debian.org>
Changes:
exim4 (4.92-8+deb10u6) buster-security; urgency=high
.
* Fix several security vulnerabilities reported by Qualys and add related
robustness improvements. (Originally fixed in upstream release 4.94.3 and
in upstream GIT branch exim-4.92.3+fixes. (Special thanks to Heiko)
+ CVE-2020-28025: Heap out-of-bounds read in pdkim_finish_bodyhash()
+ CVE-2020-28018: Use-after-free in tls-openssl.c
+ CVE-2020-28023: Out-of-bounds read in smtp_setup_msg()
+ CVE-2020-28010: Heap out-of-bounds write in main()
+ CVE-2020-28011: Heap buffer overflow in queue_run()
+ CVE-2020-28013: Heap buffer overflow in parse_fix_phrase()
+ CVE-2020-28017: Integer overflow in receive_add_recipient()
+ CVE-2020-28022: Heap out-of-bounds read and write in extract_option()
+ CVE-2020-28026: Line truncation and injection in spool_read_header()
+ CVE-2020-28015 and CVE-2020-28021: New-line injection into spool header
file.
+ CVE-2020-28009: Integer overflow in get_stdinput()
+ CVE-2020-28024: Heap buffer underflow in smtp_ungetc()
+ CVE-2020-28012: Missing close-on-exec flag for privileged pipe
+ CVE-2020-28019: Failure to reset function pointer after BDAT error
+ CVE-2020-28007: Link attack in Exim's log directory
+ CVE-2020-28008: Assorted attacks in Exim's spool directory
+ CVE-2020-28014, CVE-2021-27216: Arbitrary PID file creation, clobbering,
and deletion.
Checksums-Sha1:
54c7404eb113857d8fe5a877eb2397543b426edc 2855 exim4_4.92-8+deb10u6.dsc
4ed2ff740800d30070b1a3dcd427e0a4472b790f 497216 exim4_4.92-8+deb10u6.debian.tar.xz
Checksums-Sha256:
e9bf1b8c6c04ab556b5b6e9badcffb8f4e1dfd6a41c9645acd7328ddcb70fe93 2855 exim4_4.92-8+deb10u6.dsc
485766d69f748d3b3a4b4318571c4d830c7dcc7c91113ede0115ac3c8b1db9d0 497216 exim4_4.92-8+deb10u6.debian.tar.xz
Files:
b3b3534edaa8bb1a12ec93aba454ad6d 2855 mail standard exim4_4.92-8+deb10u6.dsc
422839ddeebeb5a16d4041154fa842b9 497216 mail standard exim4_4.92-8+deb10u6.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmCOxyEACgkQpU8BhUOC
FIQUBBAAmhhUxoHC6cZrawG+Pg4RsH/LBTeyx/X61s6UvYslh03J5ShaBy5g8aaF
/fXdMWbjcpQ06U1oob6LoUvCeZryOlhxq/ihesALtXUQUgeQFTpouEAZpHqf0XQq
NfM5zHUqcxI0Qxi6Acw6YUVRjHG1LfhNClCvVfdWuLHTrD3HUSu7qhEB48uh9wpt
q4UEjYTLAkQPs3SgP821FAzg4fOmNqKqo48x7Evb8P1z8q/TayGKr1zAxqyVBskK
iZQvgYOLaByvw5wtJxMhnNkV2IP25jvAvL+a8D3Zun7AdryzOmCXWo5TpHdhhEMl
b3/NNc0ZZdVmNdMv90i/3s7XUjRQ9kIV4uVGOVOhr+PukbfCPwz/oDYwwWGTEjek
ivQx7IQcPWosR1pya1GUHtNSzIecw3AdnxYcShOFnm0oMPZEle6SKZvNgQZKurg1
70Pt0UlVctqJFnyUFUIchZ5YIn9n3b0oaTIajtElXlPpa3Hl2BTIKm6ACsndASvO
+xBePlh1HnaAzzPv4Yfhu1CZUXeW8FCZtkq/ooo6pvFX0YAirdQHtM6LqfPReGl3
7DLmyo6/Jn9xAzuOzYFJd9k04dhkK9Jx2KZastnVKamOG+hVSI3URc/H1PJ3y/WK
LEjAl6mTjn/+/zVbCKDGvruCeTvKBrgtodfVIOkhVjPMHcCoIEA=
=2iK8
-----END PGP SIGNATURE-----
Thank you for your contribution to Debian.
More information about the Pkg-exim4-maintainers
mailing list