|
|
Subscribe / Log in / New account

Debian alert DLA-1911-1 (exim4)

From:  Thorsten Alteholz <debian@alteholz.de>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 1911-1] exim4 security update
Date:  Fri, 6 Sep 2019 12:38:28 +0200 (CEST)
Message-ID:  <alpine.DEB.2.20.1909061229380.25570@jupiter.server.alteholz.net>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : exim4 Version : 4.84.2-2+deb8u6 CVE ID : CVE-2019-15846 "Zerons" and Qualys discovered that a buffer overflow triggerable in the TLS negotiation code of the Exim mail transport agent could result in the execution of arbitrary code with root privileges. For Debian 8 "Jessie", this problem has been fixed in version 4.84.2-2+deb8u6. We recommend that you upgrade your exim4 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl1yNyRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7 WEeDHBAAsTIcEg9+pytEspkf5NuPyvcJK9zh4uiHj6ONTudl+HDUSAt3e+4h7iAK gqWXjyorvevZ8Tf6OkxWxNFV3AiBWiVzH6Qo5/urCz1fogSuJQKj8wTjgp8voM8F hfcLOP9UYEEAMnWQtZRAaTt9WbkGcgzXukhyv8yfR6yCwxiKycP99qvPWtAifJhN idXLx8EE7P6m8s4c4HW+9soGyEW1/Jl2XR210VIZhN1gpT9EHlm5aH4FGm8dedGB Tpfa8m0B+AOAAaaNuv9XExXSVDlaYCHt308EIAgn2j0OfXAPQQROp5Ps8n8UJCAC IYYD8eAI8g686DON16PIzgfzuvbPXudxQnxH9347MUGOwXm9eFazgM/g+NExxyL8 HVQsSwaUT3XF9sfdXnTCvf/d04wqyRdwzwNpCi8VzwBRAo3zqixvd1YTaBbhk+Rq nBYwPUJcqquNzJ8lW71XnXT407hoB9B57iolAbi6H86G1/sWESgGfHG/Z7/VvdGu xj9i0vwip9UnSdpTSDXzrEaTAGRK2JEFUiGPHtEAJYAebMDI4aRKlJ05k8+7oCbD 7NxcwvAf9OWhdJD9rwrd6BTrEDbolxdz/e1Mk4rVZt48XnMLmaTxpoKIPsiO6Yvg X2+W3jPPQ2Cd7ORSaH6tLoZjTdCA2eR6TUqI925XjSbQCupf0aM= =8NPw -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds