Debian Security Advisory
DLA-2650-1 exim4 -- LTS security update
- Date Reported:
- 05 May 2021
- Affected Packages:
- exim4
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2020-28007, CVE-2020-28008, CVE-2020-28009, CVE-2020-28011, CVE-2020-28012, CVE-2020-28013, CVE-2020-28014, CVE-2020-28015, CVE-2020-28017, CVE-2020-28019, CVE-2020-28020, CVE-2020-28021, CVE-2020-28022, CVE-2020-28023, CVE-2020-28024, CVE-2020-28025, CVE-2020-28026.
- More information:
-
The Qualys Research Labs reported several vulnerabilities in Exim, a mail transport agent, which could result in local privilege escalation and remote code execution.
Details can be found in the Qualys advisory at https://www.qualys.com/2021/05/04/21nails/21nails.txt
For Debian 9 stretch, these problems have been fixed in version 4.89-2+deb9u8.
We recommend that you upgrade your exim4 packages.
For the detailed security status of exim4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/exim4
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS