Thread View: gmane.mail.exim.announce
1 messages
1 total messages
Started by Heiko Schlitterm
Mon, 22 Jul 2019 12:02
CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead
Author: Heiko Schlitterm
Date: Mon, 22 Jul 2019 12:02
Date: Mon, 22 Jul 2019 12:02
125 lines
4232 bytes
4232 bytes
--===============0669804055== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="VSaCG/zfRnOiPJtU" Content-Disposition: inline --VSaCG/zfRnOiPJtU Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable *** Note: EMBARGO is still in effect until July 25th, 10:00 UTC. *** *** Distros must not publish any detail nor release updates yet. *** CVE ID: CVE-2019-13917 OVE ID: OVE-20190718-0006 Date: 2019-07-18 Credits: Jeremy Harris Version(s): 4.85 up to and including 4.92 Issue: A local or remote attacker can execute programs with root privileges - if you've an unusual configuration. For details see below. Coordinated Release Date (CRD) for Exim 4.92.1: Thu Jul 25 10:00:00 UTC 2019 Contact: security@exim.org This is a *heads-up* notice about the upcoming release. You may plan your availability and schedule an update of the Exim packages supplied by your distribution or build the new release from the source, once the release goes public on CRD. Details =3D=3D=3D=3D=3D=3D=3D We discovered a vulnerability. We consider the risk of an exploit as low, you need to have a fairly unusual runtime configuration. Neither our default runtime configuration nor the runtime configuration shipped by the Debian distribution is vulnerable. The vulnerability is exploitable either remotely or locally and could be used to execute other programs with root privilege. More details and fixes are not yet public, but will be made public on CRD, July 25th. Timeline =3D=3D=3D=3D=3D=3D=3D=3D t0: Thu Jul 18 2019 - this notice to distros@vs.openwall.org and exim-maintainers@exim.org - open limited access to our security Git repo. See below. t0+~4d: Mon Jul 22 10:00:00 UTC 2019 [NOW] - heads-up notice to oss-security@lists.openwall.com, exim-users@exim.org, and exim-announce@exim.org t0+~7d: Thu Jul 25 10:00:00 UTC 2019 - Coordinated relase date - publish the patches in our official and public Git repositories and the packages on our FTP server. Downloads available starting at CRD =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D For release tarballs (exim-4.92.1): http://ftp.exim.org/pub/exim/exim4/ The package files are signed with my GPG key. For the full Git repo: https://git.exim.org/exim.git https://github.com/Exim/exim [mirror of the above] - tag exim-4.92.1 - branch exim-4.92.1+fixes The tagged commit is the officially released version. The tag is signed with my GPG key. The +fixes branch isn't officially maintained, but contains useful patches *and* the security fix. The relevant commit is signed with my GPG key. The old exim-4.92+fixes branch is being functionally replaced by the new exim-4.92.1+fixes branch. Best regards from Dresden/Germany Viele Gr=C3=BC=C3=9Fe aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---------------------------- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --------------- key ID: F69376CE - ! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ - --VSaCG/zfRnOiPJtU Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEE0L/WueylaUpvFJ3Or0zGdqa2wUIFAl01icUACgkQr0zGdqa2 wUIiIwf/RIrQ/9WLyrv9Ommtvgi7dICNKikFZdKSVVzdPrnkqM0KrXvg5gSyOV09 i48JYapt08BYSiG5nstskn/tVWsbjCMgV7SdBQx5792ZwAdHLzikoEJtcMwdjMbM VbaogDY4P7EvZhFvbx++4+xEynR+GYbcqVsv3eUxolRVyd0V7l+4mO55HZN5GKAh PfUXUEUidFZsLOWvk1GvOObkULg6kwH55uADIgSxngL3wUKpfRRfl6NXNSF2zWpz LnHSLtNRJsB4BMxc9s9kAbEr/4ZqTWU/Rub8yf2Edo4fxU8qNY32QpLQcmKxHVHE TAx2m5gra5SNl2qUIyFDuN+S/QvTgA== =NhPW -----END PGP SIGNATURE----- --VSaCG/zfRnOiPJtU-- --===============0669804055== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ## List details at https://lists.exim.org/mailman/listinfo/exim-announce Exim details at http://www.exim.org/ ## --===============0669804055==--
Thread Navigation
This is a paginated view of messages in the thread with full content displayed inline.
Messages are displayed in chronological order, with the original post highlighted in green.
Use pagination controls to navigate through all messages in large threads.
Back to All Threads