Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in Exim
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in Exim
ID: USN-4520-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS
Datum: Sa, 19. September 2020, 10:07
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19920
Applikationen: exim

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============5971805153712664681==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="xHYheIrqm9HFIxNZosbi0lawEuLxaxisP"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--xHYheIrqm9HFIxNZosbi0lawEuLxaxisP
Content-Type: multipart/mixed;
boundary="fuj5k6Nvt1BwWD54199eSL9K8rdn1g1PE"

--fuj5k6Nvt1BwWD54199eSL9K8rdn1g1PE
Content-Type: text/plain; charset=utf-8
Content-Language: en-U
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4520-1
September 18, 2020

sa-exim vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Exim SpamAssassin could be made to execute aribitrary code if it
received crafted .cf files/rules.

Software Description:
- sa-exim: SpamAssassin filter for Exim

Details:

It was discovered that Exim SpamAssassin does not properly handle
configuration strings. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2019-19920)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
sa-exim 4.2.1-14+deb8u1build0.16.04.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4520-1
CVE-2019-19920

Package Information:
https://launchpad.net/ubuntu/+source/sa-exim/4.2.1-14+deb8u1build0.16.04.1


--fuj5k6Nvt1BwWD54199eSL9K8rdn1g1PE--

--xHYheIrqm9HFIxNZosbi0lawEuLxaxisP
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7MowLJorxPNkyBZZW+PTAFZKyRgFAl9lSfQACgkQW+PTAFZK
yRgrLBAAxwoaEX4McKCS0X6tAn/+bhQJJLZpZoR+2rUXTHrovBnCe/fHfVpjDsr4
8lgDgkk1ztKnmRHKo8AUYDcUeAW2Vg/hPAGp/023CEYzIoJ3lIaLXaBLNc91sCaH
uVb99L0tZre3lH6g69H6J4ZEvVrDnXgp3kYXlVr1eX6xZPAHInzxrOuW1tNi/IDs
AHAWzHtDinSLD2l4ew+mKQGGbjkXhfdArDvNxyBDo+IFoyjhrB/rEqLzvsgAZlu0
11nj9k/gSnSbWaKi8fENpeBtfFxkcmE4j0HEFakQ6Z4yGq428MRmIBamF9XvGK7W
sEBWmj5YtKATDM0yzmcLSADiZJ8edb22Rne+WmmHd0/KqV6SXBeBT7RGl2seQQ+C
KknAZM+c+TtvHrVPOxqZGAIWNzo8XeoNRktEFs+Ul4Mc4bKXF3e/SktiodqFDD0B
54QUYjh7H7U3h3h7/Y51sjhdJQhvVAksXxXnwdqwn5QIR5F/evm7F7cciQu0nM5N
8FO/FpHXGnRqJC/yoI/g7JNps/oOxJYax5hm4jCKite9YeAG9U/yuDmKqo8qMKUs
whmbc+TajLhwhqbxdOW9E/GFJxSa2icCf+lSnCe30Az1vgmDZ4SbGP6MJf61YE9E
tKthtnmyMwiREtB02clQQyBZgpFUvquljCs/5c6CByvPUzRM/tQ=
=oUOo
-----END PGP SIGNATURE-----

--xHYheIrqm9HFIxNZosbi0lawEuLxaxisP--


--===============5971805153712664681==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============5971805153712664681==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung