UbuntuUpdates.org

Package "exim4-dev"

Name: exim4-dev

Description:

header files for the Exim MTA (v4) packages

Latest version: 4.93-13ubuntu1.10
Release: focal (20.04)
Level: security
Repository: main
Head package: exim4
Homepage: https://www.exim.org/

Links


Download "exim4-dev"


Other versions of "exim4-dev" in Focal

Repository Area Version
base main 4.93-13ubuntu1
updates main 4.93-13ubuntu1.10

Changelog

Version: 4.93-13ubuntu1.5 2021-05-04 15:07:15 UTC

  exim4 (4.93-13ubuntu1.5) focal-security; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/sec-202105/*.patch: backport patches from upstream to
      correct issues.
    - CVE-2020-28007, CVE-2020-28008, CVE-2020-28009, CVE-2020-28010,
      CVE-2020-28011, CVE-2020-28012, CVE-2020-28013, CVE-2020-28014,
      CVE-2020-28015, CVE-2020-28016, CVE-2020-28017, CVE-2020-28018,
      CVE-2020-28019, CVE-2020-28021, CVE-2020-28022, CVE-2020-28023,
      CVE-2020-28024, CVE-2020-28025, CVE-2020-28026, CVE-2021-27216

 -- Marc Deslauriers <email address hidden> Wed, 28 Apr 2021 09:19:17 -0400

Source diff to previous version

Version: 4.93-13ubuntu1.1 2020-05-19 14:06:35 UTC

  exim4 (4.93-13ubuntu1.1) focal-security; urgency=medium

  * SECURITY UPDATE: Out-of-bounds read
    - debian/patches/CVE-2020-12783-*.patch: fix SPA
      authenticator, checking client-supplied data before using it
      in src/auths/spa.c, src/auths/spa-spa.c.
    - CVE-2020-12783

 -- <email address hidden> (Leonidas S. Barbosa) Thu, 14 May 2020 10:29:45 -0300

CVE-2020-12783 Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/aut



About   -   Send Feedback to @ubuntu_updates