|
|
Subscribe / Log in / New account

Exim 4.92.3 security release

Exim 4.92.3 security release

[Security] Posted Sep 30, 2019 15:12 UTC (Mon) by ris

Exim 4.92.3 has been released with a fix for CVE-2019-16928, a heap-based buffer overflow in string_vformat that could lead to remote code execution. "The currently known exploit uses a extraordinary long EHLO string to crash the Exim process that is receiving the message. While at this mode of operation Exim already dropped its privileges, other paths to reach the vulnerable code may exist."

Full Story (comments: 5)


Copyright © 2019, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds