DSA-5512-1 exim4 -- security update

Related Vulnerabilities: CVE-2023-42114   CVE-2023-42115   CVE-2023-42116  

Several vulnerabilities were discovered in Exim, a mail transport agent, which could result in remote code execution if the EXTERNAL or SPA/NTLM authenticators are used. For the oldstable distribution (bullseye), these problems have been fixed in version 4.94.2-7+deb11u1. For the stable distribution (bookworm), these problems have been fixed in version 4.96-15+deb12u2. We recommend that you upgrade your exim4 packages. For the detailed security status of exim4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/exim4

Debian Security Advisory

DSA-5512-1 exim4 -- security update

Date Reported:
02 Oct 2023
Affected Packages:
exim4
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2023-42114, CVE-2023-42115, CVE-2023-42116.
More information:

Several vulnerabilities were discovered in Exim, a mail transport agent, which could result in remote code execution if the EXTERNAL or SPA/NTLM authenticators are used.

For the oldstable distribution (bullseye), these problems have been fixed in version 4.94.2-7+deb11u1.

For the stable distribution (bookworm), these problems have been fixed in version 4.96-15+deb12u2.

We recommend that you upgrade your exim4 packages.

For the detailed security status of exim4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/exim4