==========================================================================
Ubuntu Security Notice USN-4010-1
June 05, 2019
exim4 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 18.10
– Ubuntu 18.04 LTS
Summary:
Exim could be made to run commands if it received specially crafted network
traffic.
Software Description:
– exim4: Exim is a mail transport agent
Details:
It was discovered that Exim incorrectly handled certain decoding
operations. A remote attacker could possibly use this issue to execute
arbitrary commands.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.10:
exim4-daemon-heavy 4.91-6ubuntu1.1
exim4-daemon-light 4.91-6ubuntu1.1
Ubuntu 18.04 LTS:
exim4-daemon-heavy 4.90.1-1ubuntu1.2
exim4-daemon-light 4.90.1-1ubuntu1.2
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4010-1
CVE-2019-10149
Package Information:
https://launchpad.net/ubuntu/+source/exim4/4.91-6ubuntu1.1
https://launchpad.net/ubuntu/+source/exim4/4.90.1-1ubuntu1.2
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlz37kgACgkQZWnYVadE
vpNaFhAAs8BOWKZ9L2gN0OlyKS/5JcCewtP5RE0+67/XiTv//F+psoXMy0ZYAiQ7
Uv0e2hlLRn4RneMMKkLCdOAzHSXnV7p+nH0oPXITwQEwQlQJn6YNxs4J0Af0QCT2
EefXl0CeTKUmaTfjviPInK+41ZUif/jLCXevFgCO9oIDB98ubl66/KCpt9Be/Aye
v0YXw2RTpMvxoWaQ1xB946vZIlUBUFfpDmhRWehokMJFMH1KUM/ZHwcXHctHsMkD
j40nhyTz7v5p/rqPINtsEdlxRpjcBklFfGyKm4oaW0hDWGGeSy/2Ea3x6ybH8XwE
w57ttCl6uhlwfzjsMy0zl36ryaAlchV5RL5h0Azo6sYM6DcNrnInNg1DXEkKocrB
aBo+83Al5VpxhpRMw8pKcfSpxshWTzwTBhXuHc/0mQNnIC6pztI7BmdH+cfsjdz2
my4vIpwUrHLQRNYsTlPqb5+UiEqeGxDaliz+AFXxGvGteUfvqrXCbH0463FH6P+o
NeUdx7oyjnxaCwB5LArjIvAifDr6yBvNsA2XN0IlJGaZD+RxxbWTNBzi3ClgNWrO
vxjdOzGSa8fFTEAjYcHSz/Itj10QD1BiASjvZe/Ol+qw4h/Bxqawzw9XfG5Ha/Ih
MfdfEKjlu8S6C7bTaIEHJztgyziJAoHUB80BDYguYZzaav8ceMg=
=SJ+3
—–END PGP SIGNATURE—–
—