[exim] Re: Exim Zero Day?

2023-10-02 Thread Christof Meerwald via Exim-users
On Mon, 2 Oct 2023 20:54:56 +0200, Cyborg via Exim-users wrote: > That slowed it down massively and now, with the public advisories from > ZDI, the pressure was immense to find it in time and develope a working fix. But my understanding here is that fixes were actually already done in May 2023, s

[exim] Re: Exim Zero Day?

2023-10-02 Thread Christof Meerwald via Exim-users
On Mon, 2 Oct 2023 18:11:49 +0200, Andreas Metzler via Exim-users wrote: > On 2023-10-02 Christof Meerwald via Exim-users > wrote: >> On Sun, 01 Oct 2023 20:35:48 +, Slavko via Exim-users wrote: >> > Dňa 1. októbra 2023 20:07:45 UTC používateľ Christof Meerwald via >

[exim] Re: Exim Zero Day?

2023-10-01 Thread Christof Meerwald via Exim-users
On Sun, 01 Oct 2023 20:35:48 +, Slavko via Exim-users wrote: > Dňa 1. októbra 2023 20:07:45 UTC používateľ Christof Meerwald via Exim-users > napísal: >>This was only officially confirmed today (which is very unfortunate), > > That is true only in this ML, othervise i

[exim] Re: Exim Zero Day?

2023-10-01 Thread Christof Meerwald via Exim-users
On Sun, 01 Oct 2023 19:50:43 +, Slavko via Exim-users wrote: > Dňa 1. októbra 2023 17:49:26 UTC používateľ Rainer Dorsch via Exim-users > napísal: >>I stopped the exim4 service on servers with port 25 accessible from the >>internet > > Please why? > > + do you use AUTH (NTLM/EXTERNAL) on por

[exim] Re: Exim Zero Day?

2023-10-01 Thread Christof Meerwald via Exim-users
On Fri, 29 Sep 2023 15:17:05 +, Some Guy via Exim-users wrote: > Hi, I'm running an appliance which includes an Exim MTA and now I'm > wondering, if I should be worried because of the RCE with CVSS 9.8 described > at the Zero Day Initiative homepage here: > > https://www.zerodayinitiative.com