Back to exim4 PTS page

Accepted exim4 4.92-8+deb10u6 (source) into proposed-updates->stable-new, proposed-updates



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 01 May 2021 11:42:39 +0200
Source: exim4
Architecture: source
Version: 4.92-8+deb10u6
Distribution: buster-security
Urgency: high
Maintainer: Exim4 Maintainers <pkg-exim4-maintainers@lists.alioth.debian.org>
Changed-By: Andreas Metzler <ametzler@debian.org>
Changes:
 exim4 (4.92-8+deb10u6) buster-security; urgency=high
 .
   * Fix several security vulnerabilities reported by Qualys and add related
     robustness improvements. (Originally fixed in upstream release 4.94.3 and
     in upstream GIT branch exim-4.92.3+fixes. (Special thanks to Heiko)
     + CVE-2020-28025: Heap out-of-bounds read in pdkim_finish_bodyhash()
     + CVE-2020-28018: Use-after-free in tls-openssl.c
     + CVE-2020-28023: Out-of-bounds read in smtp_setup_msg()
     + CVE-2020-28010: Heap out-of-bounds write in main()
     + CVE-2020-28011: Heap buffer overflow in queue_run()
     + CVE-2020-28013: Heap buffer overflow in parse_fix_phrase()
     + CVE-2020-28017: Integer overflow in receive_add_recipient()
     + CVE-2020-28022: Heap out-of-bounds read and write in extract_option()
     + CVE-2020-28026: Line truncation and injection in spool_read_header()
     + CVE-2020-28015 and CVE-2020-28021: New-line injection into spool header
       file.
     + CVE-2020-28009: Integer overflow in get_stdinput()
     + CVE-2020-28024: Heap buffer underflow in smtp_ungetc()
     + CVE-2020-28012: Missing close-on-exec flag for privileged pipe
     + CVE-2020-28019: Failure to reset function pointer after BDAT error
     + CVE-2020-28007: Link attack in Exim's log directory
     + CVE-2020-28008: Assorted attacks in Exim's spool directory
     + CVE-2020-28014, CVE-2021-27216: Arbitrary PID file creation, clobbering,
       and deletion.
Checksums-Sha1: 
 54c7404eb113857d8fe5a877eb2397543b426edc 2855 exim4_4.92-8+deb10u6.dsc
 4ed2ff740800d30070b1a3dcd427e0a4472b790f 497216 exim4_4.92-8+deb10u6.debian.tar.xz
Checksums-Sha256: 
 e9bf1b8c6c04ab556b5b6e9badcffb8f4e1dfd6a41c9645acd7328ddcb70fe93 2855 exim4_4.92-8+deb10u6.dsc
 485766d69f748d3b3a4b4318571c4d830c7dcc7c91113ede0115ac3c8b1db9d0 497216 exim4_4.92-8+deb10u6.debian.tar.xz
Files: 
 b3b3534edaa8bb1a12ec93aba454ad6d 2855 mail standard exim4_4.92-8+deb10u6.dsc
 422839ddeebeb5a16d4041154fa842b9 497216 mail standard exim4_4.92-8+deb10u6.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmCOxyEACgkQpU8BhUOC
FIQUBBAAmhhUxoHC6cZrawG+Pg4RsH/LBTeyx/X61s6UvYslh03J5ShaBy5g8aaF
/fXdMWbjcpQ06U1oob6LoUvCeZryOlhxq/ihesALtXUQUgeQFTpouEAZpHqf0XQq
NfM5zHUqcxI0Qxi6Acw6YUVRjHG1LfhNClCvVfdWuLHTrD3HUSu7qhEB48uh9wpt
q4UEjYTLAkQPs3SgP821FAzg4fOmNqKqo48x7Evb8P1z8q/TayGKr1zAxqyVBskK
iZQvgYOLaByvw5wtJxMhnNkV2IP25jvAvL+a8D3Zun7AdryzOmCXWo5TpHdhhEMl
b3/NNc0ZZdVmNdMv90i/3s7XUjRQ9kIV4uVGOVOhr+PukbfCPwz/oDYwwWGTEjek
ivQx7IQcPWosR1pya1GUHtNSzIecw3AdnxYcShOFnm0oMPZEle6SKZvNgQZKurg1
70Pt0UlVctqJFnyUFUIchZ5YIn9n3b0oaTIajtElXlPpa3Hl2BTIKm6ACsndASvO
+xBePlh1HnaAzzPv4Yfhu1CZUXeW8FCZtkq/ooo6pvFX0YAirdQHtM6LqfPReGl3
7DLmyo6/Jn9xAzuOzYFJd9k04dhkK9Jx2KZastnVKamOG+hVSI3URc/H1PJ3y/WK
LEjAl6mTjn/+/zVbCKDGvruCeTvKBrgtodfVIOkhVjPMHcCoIEA=
=2iK8
-----END PGP SIGNATURE-----