it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 4912-1] exim4 security update
- Date: Tue, 04 May 2021 13:53:56 +0000
- Authentication-results: mail02.piratenpartei.de; dkim=none; dmarc=none; spf=none (mail02.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
- List-archive: https://lists.debian.org/msgid-search/E1ldvUq-0001wv-Nb AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=80CSF/zNAyMQonSv+SOTWf6vtbcoifLRISew9U4g6/Y=; b=EF FiAgd1fjZUP+ktM5CByVfTRjX26RYyZtWMH3OFHp9Qoy+BGKhBeOhHfVxIN1ElxKf2ny4RXm/BVnL DYd0WFxWF8/xVvFFH8Tth4F8MxnXhvyswtkER42JHq2OsmWpe8ZtN2cbyh7aeEY0+QS3qFsEhJ36p cAgE8o2iVqUQAatDnbYAJz0okaWgQtsYgLBQXUgurWTqQtmREApgob9YDSqXTPrPcup6gPlZJ8gXd 4Bx/ol1ahp1cpuFjjhrRYjK0JgiBG3VMcqj2Q32UrGBGp0Y0nH4reg3OSKra0mG4scrW3X7gLtWSv 0nzHee4dU7BLNwffo/fu20tQHa4scRFg==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Tue, 4 May 2021 13:54:16 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <yike5y1Z7NH.A.6xE.IIVkgB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4912-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
May 04, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : exim4
CVE ID : CVE-2020-28007 CVE-2020-28008 CVE-2020-28009 CVE-2020-28010
CVE-2020-28011 CVE-2020-28012 CVE-2020-28013 CVE-2020-28014
CVE-2020-28015 CVE-2020-28017 CVE-2020-28019 CVE-2020-28021
CVE-2020-28022 CVE-2020-28023 CVE-2020-28024 CVE-2020-28025
CVE-2020-28026
The Qualys Research Labs reported several vulnerabilities in Exim, a
mail transport agent, which could result in local privilege escalation
and remote code execution.
Details can be found in the Qualys advisory at
https://www.qualys.com/2021/05/04/21nails/21nails.txt
For the stable distribution (buster), these problems have been fixed in
version 4.92-8+deb10u6.
We recommend that you upgrade your exim4 packages.
For the detailed security status of exim4 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/exim4
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmCRUaJfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QLyg//fYw8UFUI3iGtSQI/G+did65XT3t4tib3Ddc9LcrqzZMQiNMpVMbcNMLB
uCtOl/pmVKS0W9BeNIPLfOwlpwxOtCZgZsmgfm5+IaMkLSkghZUMxSWNezgMaVGE
UZLp0/4Ha9Ehm8dL3TfArE3QsB3dJwAFDRknXLGw+BgilL7wWVyw8QOniqblh3zH
VYipYM/524IvLHcoxV2jU9StVr0AEE3xObMF1JwXZojtY60ZxeAwH/vW4c+cze7q
Q2TyMddFLGyotQFBrWrq1P96TvaH0oDfvoFZpxTPtNvWEiZtKvYkSk4LBUnAu9La
VMa2JUTCQe7+5gducLCftpKsPqTWYvEqDDK6M1Fo43CcAlFxzcELfmfGdmQ6o2Te
8wmYBNRjscNultb65gPa0bjNt5TCckUmZcgA9jHWp4S0RBAjEVl3aWlOBwHCWRaa
OJKWPCTuCCf7jk8zOY/BTaSBqf6CYI9O+TRWZNlec5L8JVfLpZnztPdJAIozp0UW
WggfA+LwRDdeagakS89K6DkM4KOC8wGcrIZJeC5Gp9RmA67KTOoXenN1slqbUALa
vHqldlcvs+m0vuKLdA4FEUtCrVD8n9ZoATcp5csVyzwwcEfRaP8Sjed/T/5LC9go
B9SZdzV2f0B8aOjeqOQQieqtT3qfEO85Q2l4z/7welUOOe8ug4o=
=ZIbN
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 4912-1] exim4 security update, Salvatore Bonaccorso, 04.05.2021
Archiv bereitgestellt durch MHonArc 2.6.24.