UbuntuUpdates.org

Bugs fixes in "exim4"

Origin Bug number Title Date fixed
CVE CVE-2026-94057 Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent aft 2026-09-28
CVE CVE-2026-94056 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack me 2026-09-28
CVE CVE-2026-94054 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. 2026-09-28
CVE CVE-2026-94057 Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent aft 2026-09-28
CVE CVE-2026-94056 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack me 2026-09-28
CVE CVE-2026-94054 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. 2026-09-28
CVE CVE-2026-94057 Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent aft 2026-09-28
CVE CVE-2026-94056 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack me 2026-09-28
CVE CVE-2026-94054 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. 2026-09-28
CVE CVE-2026-94057 Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent aft 2026-09-28
CVE CVE-2026-94056 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack me 2026-09-28
CVE CVE-2026-94054 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. 2026-09-28
CVE CVE-2026-94057 Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent aft 2026-09-28
CVE CVE-2026-94056 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack me 2026-09-28
CVE CVE-2026-94055 Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. 2026-09-28
CVE CVE-2026-94054 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. 2026-09-28
CVE CVE-2026-94057 Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent aft 2026-09-28
CVE CVE-2026-94056 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack me 2026-09-28
CVE CVE-2026-94055 Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. 2026-09-28
CVE CVE-2026-94054 Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. 2026-09-28



About   -   Send Feedback to @ubuntu_updates