USN-4934-2: Exim vulnerabilities

06 May 2021

Several security issues were fixed in Exim.

Releases

Packages

  • exim4 - Exim is a mail transport agent

Details

USN-4934-1 fixed several vulnerabilities in Exim. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
CVE-2020-28026 only affected Ubuntu 16.04 ESM.

Original advisory details:

It was discovered that Exim contained multiple security issues. An attacker
could use these issues to cause a denial of service, execute arbitrary
code remotely, obtain sensitive information, or escalate local privileges.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 16.04
Ubuntu 14.04

In general, a standard system update will make all the necessary changes.

Related notices

  • USN-4934-1: exim4-daemon-heavy, exim4-dev, exim4-base, exim4-daemon-light, eximon4, exim4, exim4-config