Bug#882648: exim4: remote code execution in chunking

2017-11-25 Thread Andreas Metzler
On 2017-11-25 Salvatore Bonaccorso wrote: > On Sat, Nov 25, 2017 at 11:34:56AM +0100, Andreas Metzler wrote: [...] >> please note that Debian/stable is patched to set >> chunking_advertise_hosts = >> by default. Therefore stable users should not be affected unless they >> have locally set chunki

Bug#882648: exim4: remote code execution in chunking

2017-11-25 Thread Salvatore Bonaccorso
Hi, [just some additional comments] On Sat, Nov 25, 2017 at 11:34:56AM +0100, Andreas Metzler wrote: > On 2017-11-25 Dominic Hargreaves wrote: > > Package: exim4 > > Version: 4.89-9 > > Severity: grave > > Tags: security > > Justification: remote code execution > > > - Forwarded message fro

Bug#882648: exim4: remote code execution in chunking

2017-11-25 Thread Andreas Metzler
On 2017-11-25 Dominic Hargreaves wrote: > Package: exim4 > Version: 4.89-9 > Severity: grave > Tags: security > Justification: remote code execution > - Forwarded message from Phil Pennock - [...] > With immediate effect, please apply this workaround: if you are running > Exim 4.88 or ne

Bug#882648: exim4: remote code execution in chunking

2017-11-25 Thread Dominic Hargreaves
Package: exim4 Version: 4.89-9 Severity: grave Tags: security Justification: remote code execution Source: https://lists.exim.org/lurker/message/20171125.034842.d1d75cac.en.html - Forwarded message from Phil Pennock - Date: Fri, 24 Nov 2017 22:48:42 -0500 From: Phil Pennock To: exim-an