Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 29 Sep 2023 18:06:11 +0200
From: Heiko Schlittermann <>
Subject: Exim4 MTA CVEs assigned from ZDI

Hello Exim users,

the ZDI assigned multiple CVEs to the Exim-MTA and published them

CVE            Link                                                      Exim-Bug
CVE-2023-42114  3001 fixed
CVE-2023-42115  2999 fixed
CVE-2023-42116  3000 fixed

The ZDI contacted us in June 2022. We asked about details but didn't get
answers we were able to work with.

Next contact with ZDI was in May 2023. Right after this contact we
created project bug tracker for 3 of the 6 issues. 2 high scored of them
are fixed (OOB access). A minor scored (info leak) is fixed too.

Fixes are available in a protected repository and are ready to be
applied by the distribution maintainers.

The remaining issues are debatable or miss information we need to fix

We're more than happy to provide fixes for all issues as soon as we
receive detailed information.

    Best regards from Dresden/Germany
    Viele Grüße aus Dresden
    Heiko Schlittermann
-- ---------------------------- internet & unix support -
 Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
 gnupg encrypted messages are welcome --------------- key ID: F69376CE -

Download attachment "signature.asc" of type "application/pgp-signature" (489 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.