Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in Exim
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in Exim
ID: USN-4010-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 18.10
Datum: Mi, 5. Juni 2019, 19:06
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10149
Applikationen: exim

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============2020931402380785265==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="AzMAKnuVNEK3QzJqOcnsHxpiXZDqKyMHo"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--AzMAKnuVNEK3QzJqOcnsHxpiXZDqKyMHo
Content-Type: multipart/mixed;
boundary="pjuHlb7YwNgztsA58Zimdo1LoZmcC6Zx8";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <2c146101-1340-5774-8143-a0756d7101bb@canonical.com>
Subject: [USN-4010-1] Exim vulnerability

--pjuHlb7YwNgztsA58Zimdo1LoZmcC6Zx8
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4010-1
June 05, 2019

exim4 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.10
- Ubuntu 18.04 LTS

Summary:

Exim could be made to run commands if it received specially crafted network
traffic.

Software Description:
- exim4: Exim is a mail transport agent

Details:

It was discovered that Exim incorrectly handled certain decoding
operations. A remote attacker could possibly use this issue to execute
arbitrary commands.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
exim4-daemon-heavy 4.91-6ubuntu1.1
exim4-daemon-light 4.91-6ubuntu1.1

Ubuntu 18.04 LTS:
exim4-daemon-heavy 4.90.1-1ubuntu1.2
exim4-daemon-light 4.90.1-1ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4010-1
CVE-2019-10149

Package Information:
https://launchpad.net/ubuntu/+source/exim4/4.91-6ubuntu1.1
https://launchpad.net/ubuntu/+source/exim4/4.90.1-1ubuntu1.2


--pjuHlb7YwNgztsA58Zimdo1LoZmcC6Zx8--

--AzMAKnuVNEK3QzJqOcnsHxpiXZDqKyMHo
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlz37kgACgkQZWnYVadE
vpNaFhAAs8BOWKZ9L2gN0OlyKS/5JcCewtP5RE0+67/XiTv//F+psoXMy0ZYAiQ7
Uv0e2hlLRn4RneMMKkLCdOAzHSXnV7p+nH0oPXITwQEwQlQJn6YNxs4J0Af0QCT2
EefXl0CeTKUmaTfjviPInK+41ZUif/jLCXevFgCO9oIDB98ubl66/KCpt9Be/Aye
v0YXw2RTpMvxoWaQ1xB946vZIlUBUFfpDmhRWehokMJFMH1KUM/ZHwcXHctHsMkD
j40nhyTz7v5p/rqPINtsEdlxRpjcBklFfGyKm4oaW0hDWGGeSy/2Ea3x6ybH8XwE
w57ttCl6uhlwfzjsMy0zl36ryaAlchV5RL5h0Azo6sYM6DcNrnInNg1DXEkKocrB
aBo+83Al5VpxhpRMw8pKcfSpxshWTzwTBhXuHc/0mQNnIC6pztI7BmdH+cfsjdz2
my4vIpwUrHLQRNYsTlPqb5+UiEqeGxDaliz+AFXxGvGteUfvqrXCbH0463FH6P+o
NeUdx7oyjnxaCwB5LArjIvAifDr6yBvNsA2XN0IlJGaZD+RxxbWTNBzi3ClgNWrO
vxjdOzGSa8fFTEAjYcHSz/Itj10QD1BiASjvZe/Ol+qw4h/Bxqawzw9XfG5Ha/Ih
MfdfEKjlu8S6C7bTaIEHJztgyziJAoHUB80BDYguYZzaav8ceMg=
=SJ+3
-----END PGP SIGNATURE-----

--AzMAKnuVNEK3QzJqOcnsHxpiXZDqKyMHo--


--===============2020931402380785265==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============2020931402380785265==--
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung