drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in Exim
Name: |
Ausführen beliebiger Kommandos in Exim |
|
ID: |
USN-4520-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 16.04 LTS |
|
Datum: |
Sa, 19. September 2020, 10:07 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19920 |
|
Applikationen: |
exim |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============5971805153712664681== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="xHYheIrqm9HFIxNZosbi0lawEuLxaxisP"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --xHYheIrqm9HFIxNZosbi0lawEuLxaxisP Content-Type: multipart/mixed; boundary="fuj5k6Nvt1BwWD54199eSL9K8rdn1g1PE"
--fuj5k6Nvt1BwWD54199eSL9K8rdn1g1PE Content-Type: text/plain; charset=utf-8 Content-Language: en-U Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-4520-1 September 18, 2020
sa-exim vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
Exim SpamAssassin could be made to execute aribitrary code if it received crafted .cf files/rules.
Software Description: - sa-exim: SpamAssassin filter for Exim
Details:
It was discovered that Exim SpamAssassin does not properly handle configuration strings. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-19920)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04 LTS: sa-exim 4.2.1-14+deb8u1build0.16.04.1
In general, a standard system update will make all the necessary changes.
References: https://usn.ubuntu.com/4520-1 CVE-2019-19920
Package Information: https://launchpad.net/ubuntu/+source/sa-exim/4.2.1-14+deb8u1build0.16.04.1
--fuj5k6Nvt1BwWD54199eSL9K8rdn1g1PE--
--xHYheIrqm9HFIxNZosbi0lawEuLxaxisP Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE7MowLJorxPNkyBZZW+PTAFZKyRgFAl9lSfQACgkQW+PTAFZK yRgrLBAAxwoaEX4McKCS0X6tAn/+bhQJJLZpZoR+2rUXTHrovBnCe/fHfVpjDsr4 8lgDgkk1ztKnmRHKo8AUYDcUeAW2Vg/hPAGp/023CEYzIoJ3lIaLXaBLNc91sCaH uVb99L0tZre3lH6g69H6J4ZEvVrDnXgp3kYXlVr1eX6xZPAHInzxrOuW1tNi/IDs AHAWzHtDinSLD2l4ew+mKQGGbjkXhfdArDvNxyBDo+IFoyjhrB/rEqLzvsgAZlu0 11nj9k/gSnSbWaKi8fENpeBtfFxkcmE4j0HEFakQ6Z4yGq428MRmIBamF9XvGK7W sEBWmj5YtKATDM0yzmcLSADiZJ8edb22Rne+WmmHd0/KqV6SXBeBT7RGl2seQQ+C KknAZM+c+TtvHrVPOxqZGAIWNzo8XeoNRktEFs+Ul4Mc4bKXF3e/SktiodqFDD0B 54QUYjh7H7U3h3h7/Y51sjhdJQhvVAksXxXnwdqwn5QIR5F/evm7F7cciQu0nM5N 8FO/FpHXGnRqJC/yoI/g7JNps/oOxJYax5hm4jCKite9YeAG9U/yuDmKqo8qMKUs whmbc+TajLhwhqbxdOW9E/GFJxSa2icCf+lSnCe30Az1vgmDZ4SbGP6MJf61YE9E tKthtnmyMwiREtB02clQQyBZgpFUvquljCs/5c6CByvPUzRM/tQ= =oUOo -----END PGP SIGNATURE-----
--xHYheIrqm9HFIxNZosbi0lawEuLxaxisP--
--===============5971805153712664681== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK
--===============5971805153712664681==--
|
|
|
|