USN-6611-1: Exim vulnerability
29 January 2024
Exim could be made to bypass an SPF protection mechanism if it received a specially crafted request.
Releases
Packages
- exim4 - Exim is a mail transport agent
Details
It was discovered that Exim incorrectly handled certain requests.
A remote attacker could possibly use a published exploitation technique
to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass
of an SPF protection mechanism.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.10
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
-
exim4
-
4.90.1-1ubuntu1.10+esm3
Available with Ubuntu Pro
-
exim4-base
-
4.90.1-1ubuntu1.10+esm3
Available with Ubuntu Pro
-
eximon4
-
4.90.1-1ubuntu1.10+esm3
Available with Ubuntu Pro
Ubuntu 16.04
-
exim4
-
4.86.2-2ubuntu2.6+esm6
Available with Ubuntu Pro
-
exim4-base
-
4.86.2-2ubuntu2.6+esm6
Available with Ubuntu Pro
-
eximon4
-
4.86.2-2ubuntu2.6+esm6
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.