• Accepted exim4 4.92-8+deb10u6 (source) into proposed-updates->stable-ne

    From Debian FTP Masters@21:1/5 to All on Fri May 7 17:20:01 2021
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    Format: 1.8
    Date: Sat, 01 May 2021 11:42:39 +0200
    Source: exim4
    Architecture: source
    Version: 4.92-8+deb10u6
    Distribution: buster-security
    Urgency: high
    Maintainer: Exim4 Maintainers <pkg-exim4-maintainers@lists.alioth.debian.org> Changed-By: Andreas Metzler <ametzler@debian.org>
    Changes:
    exim4 (4.92-8+deb10u6) buster-security; urgency=high
    .
    * Fix several security vulnerabilities reported by Qualys and add related
    robustness improvements. (Originally fixed in upstream release 4.94.3 and
    in upstream GIT branch exim-4.92.3+fixes. (Special thanks to Heiko)
    + CVE-2020-28025: Heap out-of-bounds read in pdkim_finish_bodyhash()
    + CVE-2020-28018: Use-after-free in tls-openssl.c
    + CVE-2020-28023: Out-of-bounds read in smtp_setup_msg()
    + CVE-2020-28010: Heap out-of-bounds write in main()
    + CVE-2020-28011: Heap buffer overflow in queue_run()
    + CVE-2020-28013: Heap buffer overflow in parse_fix_phrase()
    + CVE-2020-28017: Integer overflow in receive_add_recipient()
    + CVE-2020-28022: Heap out-of-bounds read and write in extract_option()
    + CVE-2020-28026: Line truncation and injection in spool_read_header()
    + CVE-2020-28015 and CVE-2020-28021: New-line injection into spool header
    file.
    + CVE-2020-28009: Integer overflow in get_stdinput()
    + CVE-2020-28024: Heap buffer underflow in smtp_ungetc()
    + CVE-2020-28012: Missing close-on-exec flag for privileged pipe
    + CVE-2020-28019: Failure to reset function pointer after BDAT error
    + CVE-2020-28007: Link attack in Exim's log directory
    + CVE-2020-28008: Assorted attacks in Exim's spool directory
    + CVE-2020-28014, CVE-2021-27216: Arbitrary PID file creation, clobbering,
    and deletion.
    Checksums-Sha1:
    54c7404eb113857d8fe5a877eb2397543b426edc 2855 exim4_4.92-8+deb10u6.dsc
    4ed2ff740800d30070b1a3dcd427e0a4472b790f 497216 exim4_4.92-8+deb10u6.debian.tar.xz
    Checksums-Sha256:
    e9bf1b8c6c04ab556b5b6e9badcffb8f4e1dfd6a41c9645acd7328ddcb70fe93 2855 exim4_4.92-8+deb10u6.dsc
    485766d69f748d3b3a4b4318571c4d830c7dcc7c91113ede0115ac3c8b1db9d0 497216 exim4_4.92-8+deb10u6.debian.tar.xz
    Files:
    b3b3534edaa8bb1a12ec93aba454ad6d 2855 mail standard exim4_4.92-8+deb10u6.dsc
    422839ddeebeb5a16d4041154fa842b9 497216 mail standard exim4_4.92-8+deb10u6.debian.tar.xz

    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmCOxyEACgkQpU8BhUOC FIQUBBAAmhhUxoHC6cZrawG+Pg4RsH/LBTeyx/X61s6UvYslh03J5ShaBy5g8aaF /fXdMWbjcpQ06U1oob6LoUvCeZryOlhxq/ihesALtXUQUgeQFTpouEAZpHqf0XQq NfM5zHUqcxI0Qxi6Acw6YUVRjHG1LfhNClCvVfdWuLHTrD3HUSu7qhEB48uh9wpt q4UEjYTLAkQPs3SgP821FAzg4fOmNqKqo48x7Evb8P1z8q/TayGKr1zAxqyVBskK iZQvgYOLaByvw5wtJxMhnNkV2IP25jvAvL+a8D3Zun7AdryzOmCXWo5TpHdhhEMl b3/NNc0ZZdVmNdMv90i/3s7XUjRQ9kIV4uVGOVOhr+PukbfCPwz/oDYwwWGTEjek ivQx7IQcPWosR1pya1GUHtNSzIecw3AdnxYcShOFnm0oMPZEle6SKZvNgQZKurg1 70Pt0UlVctqJFnyUFUIchZ5YIn9n3b0oaTIajtElXlPpa3Hl2BTIKm6ACsndASvO +xBePlh1HnaAzzPv4Yfhu1CZUXeW8FCZtkq/ooo6pvFX0YAirdQHtM6LqfPReGl3 7DLmyo6/Jn9xAzuOzYFJd9k04dhkK9Jx2KZastnVKamOG+hVSI3URc/H1PJ3y/WK LEjAl6mTjn/+/zVbCKDGvruCeTvKBrgtodfVIOkhVjPMHcCoIEA=
    =2iK8
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)