Re: [exim] The most used Exim version is the vulnerable one

2019-06-15 Thread Konstantin Boyandin via Exim-users
Alain D D Williams via Exim-users писал 2019-06-12 15:44: On Wed, Jun 12, 2019 at 10:21:03AM +0200, Exim Users wrote: Am 12.06.19 um 09:50 schrieb Heiko Schlittermann via Exim-users: > I'll not give more details, as I think, it's not worth having arguments > about good and bad distros. At least

Re: [exim] The most used Exim version is the vulnerable one

2019-06-13 Thread Alain D D Williams via Exim-users
On Wed, Jun 12, 2019 at 07:27:54PM +0200, Exim Users wrote: > Dave Howe via Exim-users wrote: > > On 12/06/2019 12:01, Gary Stainburn via Exim-users wrote: > >> I have just done a "yum update" on my C7 system and there was no EXIM > >> update included. Hopefully this will be resolved soon. > >

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Andreas Metzler via Exim-users
Dave Howe via Exim-users wrote: > On 12/06/2019 12:01, Gary Stainburn via Exim-users wrote: >> I have just done a "yum update" on my C7 system and there was no EXIM update >> included. Hopefully this will be resolved soon. > Was under the impression this was already resolved in 4.92 so provided

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Heiko Schlittermann via Exim-users
Dave Howe via Exim-users (Mi 12 Jun 2019 15:12:26 CEST): > On 12/06/2019 12:01, Gary Stainburn via Exim-users wrote: > > I have just done a "yum update" on my C7 system and there was no EXIM > > update included. Hopefully this will be resolved soon. > > Was under the impression this was already

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Gary Stainburn via Exim-users
On Wednesday 12 June 2019 14:12:26 Dave Howe via Exim-users wrote: > On 12/06/2019 12:01, Gary Stainburn via Exim-users wrote: > > I have just done a "yum update" on my C7 system and there was no EXIM > > update included. Hopefully this will be resolved soon. > > Was under the impression this wa

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Dave Howe via Exim-users
On 12/06/2019 12:01, Gary Stainburn via Exim-users wrote: > I have just done a "yum update" on my C7 system and there was no EXIM update > included. Hopefully this will be resolved soon. Was under the impression this was already resolved in 4.92 so provided you are on at least that, presumably n

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Konstantin Boyandin via Exim-users
12.06.2019 18:01, Gary Stainburn via Exim-users writes: > On Wednesday 12 June 2019 06:56:34 Konstantin Boyandin via Exim-users wrote: >> I maintain several CentOS 6-based servers. They will finally be replaced >> by CentOS 7-based, but it's out of my control to upgrade the >> distributions ASAP.

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Cyborg via Exim-users
Am 12.06.19 um 13:01 schrieb Gary Stainburn via Exim-users: > On Wednesday 12 June 2019 06:56:34 Konstantin Boyandin via Exim-users wrote: >> I maintain several CentOS 6-based servers. They will finally be replaced >> by CentOS 7-based, but it's out of my control to upgrade the >> distributions ASA

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Gary Stainburn via Exim-users
On Wednesday 12 June 2019 06:56:34 Konstantin Boyandin via Exim-users wrote: > I maintain several CentOS 6-based servers. They will finally be replaced > by CentOS 7-based, but it's out of my control to upgrade the > distributions ASAP. Hence, I have to do manual upgrades and monitor > security adv

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Alain D D Williams via Exim-users
On Wed, Jun 12, 2019 at 10:21:03AM +0200, Exim Users wrote: > Am 12.06.19 um 09:50 schrieb Heiko Schlittermann via Exim-users: > > I'll not give more details, as I think, it's not worth having arguments > > about good and bad distros. At least not here on this list :) > > You know about the RHEL r

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Cyborg via Exim-users
Am 12.06.19 um 09:50 schrieb Heiko Schlittermann via Exim-users: > I'll not give more details, as I think, it's not worth having arguments > about good and bad distros. At least not here on this list :) You know about the RHEL reaction to the bugreport ? "our exim is so old, it's not a bug (there

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Heiko Schlittermann via Exim-users
Niels Dettenbach via Exim-users (Di 11 Jun 2019 19:58:14 CEST): > The "initial official" date for patch releases was "officially set" by Exim > project / security list onto the 11.06.2019 (today) - so possibly some "less > aware" (LTS) distributors will use that date ("in respect for the project"

Re: [exim] The most used Exim version is the vulnerable one

2019-06-11 Thread Konstantin Boyandin via Exim-users
Hell Niels, 12.06.2019 0:58, Niels Dettenbach writes: > Am Dienstag, 11. Juni 2019, 18:57:41 CEST schrieb Konstantin Boyandin via > Exim-users: >> If I am not mistaken, CentOS 6.10 EPEL didn't apply any patches, >> original Exim 4.91 is still their last version. > > The "initial official" date f

Re: [exim] The most used Exim version is the vulnerable one

2019-06-11 Thread Niels Dettenbach via Exim-users
Am Dienstag, 11. Juni 2019, 18:57:41 CEST schrieb Konstantin Boyandin via Exim-users: > If I am not mistaken, CentOS 6.10 EPEL didn't apply any patches, > original Exim 4.91 is still their last version. The "initial official" date for patch releases was "officially set" by Exim project / securit

Re: [exim] The most used Exim version is the vulnerable one

2019-06-11 Thread Konstantin Boyandin via Exim-users
> Am 11. Juni 2019 17:10:09 MESZ schrieb Cyborg via Exim-users : >> Hi Guys, >> >> at the end of this article, is a shodan graph of exim servers in the >> wild : >> >> https://www.helpnetsecurity.com/2019/06/07/exim-cve-2019-10149/ >> >> Guess which versions are 90% of all exims out there? > > I

Re: [exim] The most used Exim version is the vulnerable one

2019-06-11 Thread Mike Brudenell via Exim-users
On Tue, 11 Jun 2019 at 17:24, Niels Dettenbach (Syndicat IT & Internet) via Exim-users wrote: > If i read right, the most major distributors (as exim maintainers too) > backported any patch or solution at least to the most used earlier versions > (still provided in their patches / sec updates - s

Re: [exim] The most used Exim version is the vulnerable one

2019-06-11 Thread Niels Dettenbach (Syndicat IT & Internet) via Exim-users
Am 11. Juni 2019 17:10:09 MESZ schrieb Cyborg via Exim-users : >Hi Guys, > >at the end of this article, is a shodan graph of exim servers in the >wild : > >https://www.helpnetsecurity.com/2019/06/07/exim-cve-2019-10149/ > >Guess which versions are 90% of all exims out there? If i read right, the

Re: [exim] The most used Exim version is the vulnerable one

2019-06-11 Thread Jeremy Harris via Exim-users
On 11/06/2019 16:10, Cyborg via Exim-users wrote: > at the end of this article, is a shodan graph of exim servers in the wild : Since it doesn't account for patch status, not especially helpful. -- Cheers, Jeremy -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exi

[exim] The most used Exim version is the vulnerable one

2019-06-11 Thread Cyborg via Exim-users
Hi Guys, at the end of this article, is a shodan graph of exim servers in the wild : https://www.helpnetsecurity.com/2019/06/07/exim-cve-2019-10149/ Guess which versions are 90% of all exims out there? ;) best regards, Marius -- ## List details at https://lists.exim.org/mailman/listinfo/exim-