You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa exim4

Sigurnosni nedostatak programskog paketa exim4

==========================================================================
Ubuntu Security Notice USN-4010-1
June 05, 2019

exim4 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.10
– Ubuntu 18.04 LTS

Summary:

Exim could be made to run commands if it received specially crafted network
traffic.

Software Description:
– exim4: Exim is a mail transport agent

Details:

It was discovered that Exim incorrectly handled certain decoding
operations. A remote attacker could possibly use this issue to execute
arbitrary commands.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
exim4-daemon-heavy 4.91-6ubuntu1.1
exim4-daemon-light 4.91-6ubuntu1.1

Ubuntu 18.04 LTS:
exim4-daemon-heavy 4.90.1-1ubuntu1.2
exim4-daemon-light 4.90.1-1ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4010-1
CVE-2019-10149

Package Information:
https://launchpad.net/ubuntu/+source/exim4/4.91-6ubuntu1.1
https://launchpad.net/ubuntu/+source/exim4/4.90.1-1ubuntu1.2

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlz37kgACgkQZWnYVadE
vpNaFhAAs8BOWKZ9L2gN0OlyKS/5JcCewtP5RE0+67/XiTv//F+psoXMy0ZYAiQ7
Uv0e2hlLRn4RneMMKkLCdOAzHSXnV7p+nH0oPXITwQEwQlQJn6YNxs4J0Af0QCT2
EefXl0CeTKUmaTfjviPInK+41ZUif/jLCXevFgCO9oIDB98ubl66/KCpt9Be/Aye
v0YXw2RTpMvxoWaQ1xB946vZIlUBUFfpDmhRWehokMJFMH1KUM/ZHwcXHctHsMkD
j40nhyTz7v5p/rqPINtsEdlxRpjcBklFfGyKm4oaW0hDWGGeSy/2Ea3x6ybH8XwE
w57ttCl6uhlwfzjsMy0zl36ryaAlchV5RL5h0Azo6sYM6DcNrnInNg1DXEkKocrB
aBo+83Al5VpxhpRMw8pKcfSpxshWTzwTBhXuHc/0mQNnIC6pztI7BmdH+cfsjdz2
my4vIpwUrHLQRNYsTlPqb5+UiEqeGxDaliz+AFXxGvGteUfvqrXCbH0463FH6P+o
NeUdx7oyjnxaCwB5LArjIvAifDr6yBvNsA2XN0IlJGaZD+RxxbWTNBzi3ClgNWrO
vxjdOzGSa8fFTEAjYcHSz/Itj10QD1BiASjvZe/Ol+qw4h/Bxqawzw9XfG5Ha/Ih
MfdfEKjlu8S6C7bTaIEHJztgyziJAoHUB80BDYguYZzaav8ceMg=
=SJ+3
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostatak programskog paketa exim4

Otkriven je sigurnosni nedostatak u programskom paketu exim4 za operacijski sustav Debian. Otkriveni nedostatak potencijalnim napadačima omogućuje izvršavanje proizvoljnog programskog...

Close