Re: [exim] CVE-2019-15846: Exim - local or remote attacker can execute programs with root privileges.

2019-09-05 Thread Heiko Schlittermann via Exim-users
*** Note: EMBARGO is still in effect! *** *** Distros must not publish any detail yet *** In case you are entitled to access the security repo: *and* use the 4.92.2+fixes branch: The branch got two new commits, fixing a small tool. This tool is not designed to process untrusted data, so the

Re: [exim] While expecting fix for CVE-2019-15846

2019-09-05 Thread Konstantin Boyandin via Exim-users
Hello Jeremy, On 05.09.2019 17:14, Jeremy Harris via Exim-users wrote: > On 05/09/2019 10:37, Konstantin Boyandin via Exim-users wrote: >> Just curious, whether Exim is regularly tested for vulnerabilities as >> it's developed? > > Please feel free to volunteer your time and expertise. Why, that

Re: [exim] While expecting fix for CVE-2019-15846

2019-09-05 Thread Jeremy Harris via Exim-users
On 05/09/2019 10:37, Konstantin Boyandin via Exim-users wrote: > Just curious, whether Exim is regularly tested for vulnerabilities as > it's developed? Please feel free to volunteer your time and expertise. -- Cheers, Jeremy -- ## List details at https://lists.exim.org/mailman/listinfo/exim-

Re: [exim] While expecting fix for CVE-2019-15846

2019-09-05 Thread Niels Dettenbach via Exim-users
Am Donnerstag, 5. September 2019, 11:37:27 CEST schrieb Konstantin Boyandin via Exim-users: > Just curious, whether Exim is regularly tested for vulnerabilities as > it's developed? This is a bit simple view onto software security. There is no internet software without any security issues as it

[exim] While expecting fix for CVE-2019-15846

2019-09-05 Thread Konstantin Boyandin via Exim-users
Hello, Just curious, whether Exim is regularly tested for vulnerabilities as it's developed? The critical security updates are being announced way too often last year. (not meaning to raise a flame, I just dislike doing emergency updates on many systems) Sincerely, Konstantin -- ## List