Bug#1053870: CVE-2023-42118 and perceived impact

2023-10-21 Thread Jeremy Stanley
On 2023-10-21 16:34:11 +0200 (+0200), Andreas Metzler wrote: > You seem to be looking at old packages, perhaps oldstable? > exim4-daemon-heavy in Debian 12 (bookworm) is linked against libspf2 > and the default configuration has hooks to enable SPF lookups via > libsp2, not spf-tools-perl. Thanks,

Bug#1053870: CVE-2023-42118 and perceived impact

2023-10-21 Thread Andreas Metzler
On 2023-10-20 Jeremy Stanley wrote: > It looks to me like the default Exim config in Debian explicitly > calls /usr/bin/spfquery.mail-spf-perl from the spf-tools-perl > package, not the libspf2 implementation supplied by the spfquery > package. Also spf-tools-perl is suggested by exim4-base, while

Bug#1053870: CVE-2023-42118 and perceived impact

2023-10-20 Thread Jeremy Stanley
It looks to me like the default Exim config in Debian explicitly calls /usr/bin/spfquery.mail-spf-perl from the spf-tools-perl package, not the libspf2 implementation supplied by the spfquery package. Also spf-tools-perl is suggested by exim4-base, while neither spfquery nor any other packages buil