> Am 11. Juni 2019 17:10:09 MESZ schrieb Cyborg via Exim-users
 <exim-users@exim.org>:
>> Hi Guys,
>>
>> at the end of this article, is a shodan graph of exim servers in the
>> wild :
>>
>> https://www.helpnetsecurity.com/2019/06/07/exim-cve-2019-10149/
>>
>> Guess which versions are 90% of all exims out there? 
> 
> If i read right, the most major distributors (as exim maintainers too)
 backported any patch or solution at least to the most used earlier versions
 (still provided in their patches / sec updates - so the "90% of vulnerable" may
 be way to high att. But 90% sound "more impressive"...ß).

If I am not mistaken, CentOS 6.10 EPEL didn't apply any patches,
original Exim 4.91 is still their last version.

So either build manually, or switch to another MTA, or hope that
"allowed chars" trick will be good enough protection.

Sincerely,
Konstantin



-- 
## List details at https://lists.exim.org/mailman/listinfo/exim-users
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
  • [exim] The mo... Cyborg via Exim-users
    • Re: [exi... Jeremy Harris via Exim-users
    • Re: [exi... Niels Dettenbach (Syndicat IT & Internet) via Exim-users
      • Re: ... Mike Brudenell via Exim-users
      • Re: ... Konstantin Boyandin via Exim-users
        • ... Niels Dettenbach via Exim-users
          • ... Konstantin Boyandin via Exim-users
            • ... Gary Stainburn via Exim-users
              • ... Cyborg via Exim-users
              • ... Konstantin Boyandin via Exim-users
              • ... Dave Howe via Exim-users
                • ... Gary Stainburn via Exim-users
                • ... Heiko Schlittermann via Exim-users
                • ... Andreas Metzler via Exim-users
                • ... Alain D D Williams via Exim-users

Reply via email to