Debian Security Advisory
DSA-3888-1 exim4 -- security update
- Date Reported:
- 19 Jun 2017
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-1000369.
- More information:
The Qualys Research Labs discovered a memory leak in the Exim mail transport agent. This is not a security vulnerability in Exim by itself, but can be used to exploit a vulnerability in stack handling. For the full details, please refer to their advisory published at: https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt
For the oldstable distribution (jessie), this problem has been fixed in version 4.84.2-2+deb8u4.
For the stable distribution (stretch), this problem has been fixed in version 4.89-2+deb9u1.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your exim4 packages.