oss-sec mailing list archives
CVE Request - Exim 4.69-4.87 - disclosure of private information
From: Heiko Schlittermann <hs () schlittermann de>
Date: Fri, 16 Dec 2016 00:36:45 +0100
Hello, please assign a CVE ID Product: Exim Versions: 4.69 -> 4.87 Impact: Possible leak of private information to a remote attacker Reference: https://bugs.exim.org/show_bug.cgi?id=1996 (placeholder currently) Requester: Heiko Schlittermann <hs () schlittermann de> (Exim Developer) Credits: Bjoern Jacke <bjoern () j3e de> If several conditions are met, Exim leaks private information to a remote attacker. A patch exists and is under testing already. Backports to older versions are under development. As soon as the tests are passed we'll send an announcement to the "Operating system distribution security contacts list" and ask for packaging fixed versions. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann - Exim developer -- SCHLITTERMANN.de ---------------------------- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --------------- key ID: F69376CE - ! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -
Attachment:
signature.asc
Description: Digital signature
Current thread:
- CVE Request - Exim 4.69-4.87 - disclosure of private information Heiko Schlittermann (Dec 15)
- Re: CVE Request - Exim 4.69-4.87 - disclosure of private information cve-assign (Dec 15)
- CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 18)
- Re: CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 20)
- Re: CVE-2016-9963 Exim private information leak Kurt H Maier (Dec 21)
- Re: CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 21)
- Re: CVE-2016-9963 Exim private information leak Kurt H Maier (Dec 21)
- Re: CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 22)
- Re: CVE-2016-9963 Exim private information leak Jeffrey Walton (Dec 22)
- Re: CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 22)
- Re: CVE-2016-9963 Exim private information leak Jeffrey Walton (Dec 22)
- CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 18)
- Re: CVE Request - Exim 4.69-4.87 - disclosure of private information cve-assign (Dec 15)