Re: [exim] CVE-2021-38371 (was: CVE-2022-37452)

2023-03-16 Thread Andreas Metzler via Exim-users
Thanks to all the involved parties for clearing this up (and obviously for handling the whole thing in the first place)! cu Andreas -- `What a good friend you are to him, Dr. Maturin. His other friends are so grateful to you.' `I sew his ears on from time to time, sure' -- ## List details at

Re: [exim] strip incoming messages of A-R headers that claim to be from our own

2023-03-16 Thread Jeremy Harris via Exim-users
On 16/03/2023 14:53, Jim Lamers via Exim-users wrote: headers_remove = Authentication-Results headers_add = "Authentication-Results: TEST" You might prefer to only do the (remove, add-stripped) sequence when there is an offending AR header present. -- Cheers, Jeremy -- ## List details at

Re: [exim] strip incoming messages of A-R headers that claim to be from our own

2023-03-16 Thread Jeremy Harris via Exim-users
On 16/03/2023 14:53, Jim Lamers via Exim-users wrote: was wondering if there are better ways to remove incoming A-R headers that claim to be from our own admd? Nope. I raised a wishlist item for it. -- Cheers, Jeremy -- ## List details at

[exim] strip incoming messages of A-R headers that claim to be from our own

2023-03-16 Thread Jim Lamers via Exim-users
Hello list, I am sorry for creating a new thread, but i had the settings for the mailinglist misconfigured and was unable to react to the thread. I am trying to implement ARC in our Exim setup. While reading experimental-spec.txt[1] I noticed the following: "Note that it would be wise to strip

Re: [exim] CVE-2021-38371 (was: CVE-2022-37452)

2023-03-16 Thread Heiko Schlittermann via Exim-users
Hi Andrew, Andrew C Aitchison via Exim-users (Mi 15 Mär 2023 21:00:11 CET): > > > www.exim.org/static/doc/security/CVE-2021-38371.txt I'll publish your announcement there. Thank you, Andrew, for preparing it. *But*, as we do not see this as a practical security issue, we'll place a notice