|
From: <debian-security-announce@lists.debian.org>
Date: Tue May 11 2004 - 10:06:13 EDT
-----BEGIN PGP SIGNED MESSAGE-----
- --------------------------------------------------------------------------
Package : exim-tls
Georgi Guninski discovered two stack-based buffer overflows in exim
CAN-2004-0399
When "sender_verify = true" is configured in exim.conf a buffer
CAN-2004-0400
When headers_check_syntax is configured in exim.conf a buffer
For the stable distribution (woody) these problems have been fixed in
The unstable distribution (sid) does not contain exim-tls anymore.
We recommend that you upgrade your exim-tls package.
Upgrade Instructions
wget url
If you are using the apt-get package manager, use the line for
apt-get update
You may use an automated update by adding the resources from the
Debian GNU/Linux 3.0 alias woody
Source archives:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2.dsc
Alpha architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_alpha.deb
ARM architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_arm.deb
Intel IA-32 architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_i386.deb
Intel IA-64 architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_ia64.deb
HP Precision architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_hppa.deb
Motorola 680x0 architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_m68k.deb
Big endian MIPS architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_mips.deb
Little endian MIPS architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_mipsel.deb
PowerPC architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_powerpc.deb
IBM S/390 architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_s390.deb
Sun Sparc architecture:
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35-3woody2_sparc.deb
These files will probably be moved into the stable distribution on
- ---------------------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
iD8DBQFAoN3VW5ql+IAeqTIRAnKkAJ96v4jsOdRiek/sOApwBimoxmF3ZACdFOIu
_______________________________________________
This archive was generated by hypermail 2.1.8 : Tue May 11 2004 - 11:06:54 EDT |
Custom Search
|