LWN: Comments on "Exim 4.92.3 security release" https://lwn.net/Articles/800917/ This is a special feed containing comments posted to the individual LWN article titled "Exim 4.92.3 security release". en-us Sun, 05 Oct 2025 16:43:46 +0000 Sun, 05 Oct 2025 16:43:46 +0000 https://www.rssboard.org/rss-specification lwn@lwn.net Exim 4.92.3 security release https://lwn.net/Articles/801265/ https://lwn.net/Articles/801265/ Comet <div class="FormattedComment"> With my Exim maintainer hat on: current development master has many fixes related to introducing a "taint" concept for sources of data, to more systematically prevent some security problems. This has triggered many cleanups and exposed some issues.<br> <p> But it means that this latest problem had already been independently fixed in git master, in a different way. So the code cleanups Jeremy is doing are yielding real benefits for robustness. The 4.92.x status sucks for everyone (but the problems getting fixed is good). 4.93 should be a marked improvement though.<br> <p> If anyone wants to poke at the current git master and spot issues and contribute fixes or bug reports, they'll be most welcome. Please help. <br> <p> Thanks, -Phil<br> </div> Fri, 04 Oct 2019 00:46:38 +0000 Exim 4.92.3 security release https://lwn.net/Articles/801178/ https://lwn.net/Articles/801178/ joey <div class="FormattedComment"> Previous exim EHLO vulnerabilites include one in 2003.<br> </div> Wed, 02 Oct 2019 22:51:07 +0000 Exim 4.92.3 security release https://lwn.net/Articles/800952/ https://lwn.net/Articles/800952/ dfsmith <div class="FormattedComment"> Before somebody points it out, the Debian version is 4.92-8+deb10u3. (Dash, not dot.)<br> </div> Mon, 30 Sep 2019 22:39:55 +0000 Exim 4.92.3 security release https://lwn.net/Articles/800951/ https://lwn.net/Articles/800951/ dfsmith <div class="FormattedComment"> Be glad someone is looking at the code and releasing fixes! Also, Debian buster went from u2 to 4.92.8+deb10u3. I'm not sure if debian4.92.8 maps to exim4.92.3 (the changelog suggests 4.92.2), however 'apt-get changelog' shows the string_vformat fix.<br> </div> Mon, 30 Sep 2019 22:36:02 +0000 Exim 4.92.3 security release https://lwn.net/Articles/800949/ https://lwn.net/Articles/800949/ Trelane <div class="FormattedComment"> Didn't we just upgrade for a severe vulnerability this month?<br> </div> Mon, 30 Sep 2019 22:03:22 +0000