Debian Security Advisory

DSA-3888-1 exim4 -- security update

Date Reported:
19 Jun 2017
Affected Packages:
exim4
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-1000369.
More information:

The Qualys Research Labs discovered a memory leak in the Exim mail transport agent. This is not a security vulnerability in Exim by itself, but can be used to exploit a vulnerability in stack handling. For the full details, please refer to their advisory published at: https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt

For the oldstable distribution (jessie), this problem has been fixed in version 4.84.2-2+deb8u4.

For the stable distribution (stretch), this problem has been fixed in version 4.89-2+deb9u1.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your exim4 packages.