unofficial mirror of bug-guix@gnu.org 
 help / color / mirror / code / Atom feed
* bug#66304: exim vulnearable to CVE-2023-42115 et al
@ 2023-10-02 10:35 Wilko Meyer
  2023-10-05 15:25 ` bug#66304: [PATCH] gnu: exim: Update to 4.96.1 Wilko Meyer
  2023-10-06 21:14 ` bug#66304: exim vulnearable to CVE-2023-42115 et al John Kehayias via Bug reports for GNU Guix
  0 siblings, 2 replies; 3+ messages in thread
From: Wilko Meyer @ 2023-10-02 10:35 UTC (permalink / raw)
  To: 66304


Hi Guix,

Exim currently has unpatched vulnearabilities regarding its EXTERNAL
Auth driver as well as its SPA/NTLM authenticator.

According to the project[0] prospective fixes seem to be around the
corner. We should probably bump the Exim version we ship to a
non-vulnearable version as soon as one is available.

[0]: https://www.exim.org/static/doc/security/CVE-2023-zdi.txt

-- 
Kind regards,

Wilko Meyer
w@wmeyer.eu




^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2023-10-06 21:14 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-10-02 10:35 bug#66304: exim vulnearable to CVE-2023-42115 et al Wilko Meyer
2023-10-05 15:25 ` bug#66304: [PATCH] gnu: exim: Update to 4.96.1 Wilko Meyer
2023-10-06 21:14 ` bug#66304: exim vulnearable to CVE-2023-42115 et al John Kehayias via Bug reports for GNU Guix

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).