🚀 go-pugleaf

RetroBBS NetNews Server

Inspired by RockSolid Light RIP Retro Guy

Thread View: gmane.mail.exim.announce
2 messages
2 total messages Started by Heiko Schlitterm Thu, 20 Feb 2025 18:36
CVE-2025-26794: Exim Security update ahead (4.98 -> 4.98.1)
#250
Author: Heiko Schlitterm
Date: Thu, 20 Feb 2025 18:36
99 lines
3399 bytes
--===============4591463201085585912==
Content-Type: multipart/signed; micalg=pgp-sha512;
	protocol="application/pgp-signature"; boundary="OpCNAosKMsmPl0VP"
Content-Disposition: inline


--OpCNAosKMsmPl0VP
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

CVE-2025-26794

Dear Exim users,

we got a vulnerability report and are going to release a security
release on Friday, Feb 21th, 2025, at 12:00 UTC (coordinated
release date).

Distribution packagers are informed already since Tuesday evening.
Exim-users and oss-security where notified yesterday (Wednesday) evening.

The reported vulnerability is limited to the current Exim version 4.98.
Older versions are not affected.

Please understand that we don't share further details yet.

The new version 4.98.1 *will* be available

via Git (branch exim-4.98+fixes, tag exim-4.98.1):
  https://code.exim.org/exim/exim.git (master repo)
  https://code.exim.org/exim/exim/releases/tag/exim-4.98.1

  https://github.com/exim/exim.git    (mirrored repo)
  https://github.com/Exim/exim/releases/tag/exim-4.98.1

as tarball:
  https://downloads.exim.org/exim4/

In case you had access to our security repo previously already, you can
fetch the patches already in advance from
   ssh://git@code.exim.org/exim/exim-distros.git
But please don't publish details.

Commits and tarballs are signed by me, with the same key that I'm using
to sign this message.

(In case you're building directly from our master branch: there are no
patches to the master branch yet.)

Thank you for using Exim.

    Best regards from Dresden/Germany
    Viele Gr=C3=BC=C3=9Fe aus Dresden
    Heiko Schlittermann
--=20
 SCHLITTERMANN.de ---------------------------- internet & unix support -
 Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
 gnupg encrypted messages are welcome --------------- key ID: F69376CE -

--OpCNAosKMsmPl0VP
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE3ZjZI1nenjwmY/KRaX8O3WgJn28FAme3aB4ACgkQaX8O3WgJ
n28Jqw/9E0xHv8EQtlumWbdU+GiV6KR9U0lwPs8ogYrFSJ8JNhwUEpqkeLX/dfqU
SsObeVmWU7uELuymDV+y2kasFzqMti+cwXOn4D/Z8ZXEFQKE1qgosxtzcRM4i9yf
MHCjn7WY0xToyAUVeF2DsShMuU1uj0Ty6SO2VXMrCNbY1Lky7xy5YWPm0tXgNi77
3RpdvPY+DEOQrRYsDTAtMoTI5Lm7MSZPHqcpw2XxYZn4mySuETanKa/KOvu4Dlb1
/whghwSMX5Iz6MYCd3cqhPiI4PbrXJdLc9nliL0lT7XLCQHbA61E5tv1pfig8Y/K
jyJU5RT8ByKbKPzJwwr6KotFYkUY4rzr85qIluEhwipI7sT0sJewbcXh0+ivanHB
A/8a0P/D0l34L6qe+S5O6zYN+5QFFDxomZN058yod8gD6Yjf6WOLPbKEr+s9ReeV
Tlj46knNy4mcS5v0wjlgi9uDWAqsHMEKH/dzqTb9Ft4XAw1hFWxWaChebuUCYx1g
2KmP8I5WCFuTWRo3ecz92BHSJasrr4UqyDdh69B7dVZ1BUEw9EHzLBtZVD0EWslB
A8I18ilch+KXtAjuGyEs+hJyZHqIQhGeK/5g0fjPg4m4Da8gNp1SnIqwGCu0svgf
+GDVl1uKlEgLj/jjRkPRa4zl/4OIGho3VBA6Yv4aRwfzQ3qOqIc=
=9PHK
-----END PGP SIGNATURE-----

--OpCNAosKMsmPl0VP--

--===============4591463201085585912==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


-- 
## subscription configuration (requires account):
##   https://lists.exim.org/mailman3/postorius/lists/exim-announce.lists.exim.org/
## unsubscribe (doesn't require an account):
##   exim-announce-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/

--===============4591463201085585912==--
Re: CVE-2025-26794: Exim Security update ahead (4.98 -> 4.98.1)
#251
Author: Heiko Schlitterm
Date: Fri, 21 Feb 2025 13:14
64 lines
2297 bytes
--===============6703330435641884159==
Content-Type: multipart/signed; micalg=pgp-sha512;
	protocol="application/pgp-signature"; boundary="T+WRxalO50jyd3Oi"
Content-Disposition: inline


--T+WRxalO50jyd3Oi
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Exim 4.98.1 is released to the public.

It addresses a SQL injection. Please read https://exim.org/static/doc/secur=
ity/CVE-2025-26794.txt
to decide whether you need to rush.

    Best regards from Dresden/Germany
    Viele Gr=C3=BC=C3=9Fe aus Dresden
    Heiko Schlittermann
--=20
 SCHLITTERMANN.de ---------------------------- internet & unix support -
 Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
 gnupg encrypted messages are welcome --------------- key ID: F69376CE -

--T+WRxalO50jyd3Oi
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE3ZjZI1nenjwmY/KRaX8O3WgJn28FAme4bggACgkQaX8O3WgJ
n28e1g//RkWMGeKcKzirCwvrgp8EVPA921smZHFR+xUN4TUkHu1yLHGS4cAmZNlS
FzsSqZETZdKDFhP/ERRow7gt6RZBv31q/45EJC/kwmviL7quVG5lIQq1iDYuzjv/
Dd+y2Q4tgW0l9uYSGLQ2POmKtDTp6K8VUuD5D2vpsHOBY0oFT36Qlfbof+V844gV
+OvxFRpE+SdzRuuiXADzhMkXZ/ampN8O2pnmofe/53MlHotUPNS9t3PzFNa9mLUU
rS/m6eLPkZD6/wvUDk1i4OyRun2TPQ8GEkVPu3gDTVuMOWnAfY7cEG0osEB2ns8R
pTVawJwmdX1pkDw0H0o9s9f6PllwoKMV2/dH0yHMQ3n7yz8XMtZMT95yBLb3nBwl
KNIMnCmZ70wcn5RsuSDNBJlVLonPnw3Wpp2c8JhA+nzyhViWuzjSe0rkRDLbOWQg
y1AWgHspTWmP6TynXdU8gcKc+XqdBAovUP35h73jnOftqi71r5wGVsO6cRqnwhl4
Qve4H0/3T5SN9NIVv0bws8bMR4bZV1r7b27dfQtmOJHd2qBdm52I5OBxvnD5Jodj
+rlqM9Z5WHYwVqiLXS6lCRU++r/1WocpgAPekq985sonE67EtU/KXv5ScQfhp9iv
+3LZQVmHVeLy0PeXyJLL6UjjD418Devf3jhOYPz1qZ5C0mpN/08=
=JNo+
-----END PGP SIGNATURE-----

--T+WRxalO50jyd3Oi--

--===============6703330435641884159==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


-- 
## subscription configuration (requires account):
##   https://lists.exim.org/mailman3/postorius/lists/exim-announce.lists.exim.org/
## unsubscribe (doesn't require an account):
##   exim-announce-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/

--===============6703330435641884159==--
Thread Navigation

This is a paginated view of messages in the thread with full content displayed inline.

Messages are displayed in chronological order, with the original post highlighted in green.

Use pagination controls to navigate through all messages in large threads.

Back to All Threads