USN-4934-2: Exim vulnerabilities
6 May 2021
Several security issues were fixed in Exim.
- exim4 - Exim is a mail transport agent
USN-4934-1 fixed several vulnerabilities in Exim. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
CVE-2020-28026 only affected Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Exim contained multiple security issues. An attacker
could use these issues to cause a denial of service, execute arbitrary
code remotely, obtain sensitive information, or escalate local privileges.
The problem can be corrected by updating your system to the following package versions:
- exim4-base - 4.86.2-2ubuntu2.6+esm1
- exim4-daemon-heavy - 4.86.2-2ubuntu2.6+esm1
- exim4-daemon-light - 4.86.2-2ubuntu2.6+esm1
- exim4-base - 4.82-3ubuntu2.4+esm3
- exim4-daemon-heavy - 4.82-3ubuntu2.4+esm3
- exim4-daemon-light - 4.82-3ubuntu2.4+esm3
In general, a standard system update will make all the necessary changes.
- USN-4934-1: exim4-daemon-light, eximon4, exim4-config, exim4-daemon-heavy, exim4, exim4-dev, exim4-base