Your message dated Fri, 23 Feb 2018 13:32:42 +0000
with message-id <e1epdss-0002l4...@fasolo.debian.org>
and subject line Bug#890000: fixed in exim4 4.84.2-2+deb8u5
has caused the Debian Bug report #890000,
regarding exim4: CVE-2018-6789: Buffer overflow in an utility function
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
890000: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=890000
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: exim4
Version: 4.90-1
Severity: grave
Tags: security upstream

Hi,

the following vulnerability was published for exim4 (actually not
really the details, filling the bug for having a tracking bug in the
BTS).

CVE-2018-6789[0]:
| An issue was discovered in the SMTP listener in Exim 4.90 and earlier.
| By sending a handcrafted message, a buffer overflow may happen in a
| specific function. This can be used to execute code remotely.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-6789
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6789
[1] https://exim.org/static/doc/security/CVE-2018-6789.txt

Please adjust the affected versions in the BTS as needed, when issue
goes public with details and possibly adjust severity.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: exim4
Source-Version: 4.84.2-2+deb8u5

We believe that the bug you reported is fixed in the latest version of
exim4, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 890...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <car...@debian.org> (supplier of updated exim4 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 10 Feb 2018 10:16:21 +0100
Source: exim4
Binary: exim4-base exim4-config exim4-daemon-light exim4 exim4-daemon-heavy 
eximon4 exim4-dbg exim4-daemon-light-dbg exim4-daemon-heavy-dbg exim4-dev
Architecture: all source
Version: 4.84.2-2+deb8u5
Distribution: jessie-security
Urgency: high
Maintainer: Exim4 Maintainers <pkg-exim4-maintain...@lists.alioth.debian.org>
Changed-By: Salvatore Bonaccorso <car...@debian.org>
Closes: 890000
Description: 
 exim4      - metapackage to ease Exim MTA (v4) installation
 exim4-base - support files for all Exim MTA (v4) packages
 exim4-config - configuration for the Exim MTA (v4)
 exim4-daemon-heavy - Exim MTA (v4) daemon with extended features, including 
exiscan-ac
 exim4-daemon-heavy-dbg - debugging symbols for the Exim MTA "heavy" daemon
 exim4-daemon-light - lightweight Exim MTA (v4) daemon
 exim4-daemon-light-dbg - debugging symbols for the Exim MTA "light" daemon
 exim4-dbg  - debugging symbols for the Exim MTA (utilities)
 exim4-dev  - header files for the Exim MTA (v4) packages
 eximon4    - monitor application for the Exim MTA (v4) (X11 interface)
Changes:
 exim4 (4.84.2-2+deb8u5) jessie-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * Fix base64d() buffer size (CVE-2018-6789) (Closes: #890000)
Checksums-Sha1: 
 48a34cfe89f5c3ddb905b226b2ebbfb8d669ae2f 2982 exim4_4.84.2-2+deb8u5.dsc
 2a8c5b532a3cbfb0192750bede4e5c3f3a084b69 425092 
exim4_4.84.2-2+deb8u5.debian.tar.xz
 9d6c4ba7027272ee052b2cec50514a4cb61fd815 502750 
exim4-config_4.84.2-2+deb8u5_all.deb
 286ae497278ea30be3bad0bc7c87ee4ac0d4b0b7 8542 exim4_4.84.2-2+deb8u5_all.deb
Checksums-Sha256: 
 61ebdcb9be9ed4ac81fb3124748b3c259002dd51b8005c2cb29c552eae07df72 2982 
exim4_4.84.2-2+deb8u5.dsc
 c45062b4020cb2d8445ededc57563deb0ef5c4b1c00cdf0263e19f1766c7ace2 425092 
exim4_4.84.2-2+deb8u5.debian.tar.xz
 3843edbc843663d214cae81e385177e0905734fd8febe46afb813f9b24ef7a92 502750 
exim4-config_4.84.2-2+deb8u5_all.deb
 29117c0cda2b1978edc89e48b629222e1775625a93b960daa3801745f523c145 8542 
exim4_4.84.2-2+deb8u5_all.deb
Files: 
 7229009e5a60ea446b42be42239bd85a 2982 mail standard exim4_4.84.2-2+deb8u5.dsc
 8934cc358158aa68cde08379f8b62b7f 425092 mail standard 
exim4_4.84.2-2+deb8u5.debian.tar.xz
 dee73d34021ed51019fb8ce397dc90ff 502750 mail standard 
exim4-config_4.84.2-2+deb8u5_all.deb
 304d5596bd09e96cea4b366ce0c5c276 8542 mail standard 
exim4_4.84.2-2+deb8u5_all.deb

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlp++i1fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EjK4P/jD2S3DNPfBvcLGbdx+4kkaGz4nA4afL
dORn58NlX1Ui/2K8fGJ1gBBuxtoPsd10ZJseg9XihuJqADbdECXTms/dRib6IdaT
ucNKc+6rhFn/wb0HH7vbO/cCmdr22v7Ag7XF7IyvH8HcSn9FZUoAXVA5Y2iG53T5
qFcvG8HMx43stBDmORjlOGBCxN0VVGkpiS5q6pohikqkEXQRTqdBw3Au3UfD4cMR
uEsUehf+Hvf0/EyqT3nSpoWvtlU3Jqd2ce1xUL5sWAbVdM4kgh4AeBKHMuP53QXT
NJ3U7dlW3LfmUP/y22U1HCBAWwpZ4cxjiiC+3KTR87n9vsVhKvuNVg12u4vnVGpb
yckTcMfNDm/syVj0Yf2kPePkW9xPALX81hnhTy/DSlmiB8+5cOnSEr7SPnNGT7GK
DCqCHEVJIthNdhPI2xD856NtXWMxzwSNk4QkiodSSW4ThXd9qOEP2iDZXpeGY6VR
sEEWpcplQCsiGXYD69HBNuSiF7gGQpKNZUTSKXWKETrpyFED9cQvNH3i7tD0Wgi7
ifPcgWmtDZ/kg67+5hSL6TxrR0WToLOsBaY+VyrAFTPcriCUvNmPogvhE3edqWpb
13wRVqZswsIm8iv6ZzKYZIEYBFVH7841Eujx7qsEYpqiYjAI8r6vV+tsNjoKHs6W
7n4KkzVBruH2
=DI6x
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to