A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper
validation of recipient address in deliver_message() function in
src/deliver.c may lead to remote command execution.
For more details, see the advisory:
https://www.exim.org/static/doc/security/CVE-2019-10149.txt
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit
|
||
---|---|---|
.. | ||
0001-Build-buildconfig-for-the-host.patch | ||
0002-Don-t-make-backup-copies-of-installed-files.patch | ||
0003-Skip-version-check-and-symlink-installation.patch | ||
0004-glibc.patch | ||
0005-Fix-base64d-buffer-size-CVE-2018-6789.patch | ||
0006-remove-libnsl.patch | ||
0007-Fix-CVE-2019-10149.patch | ||
Config.in | ||
exim.hash | ||
exim.mk | ||
exim.service | ||
S86exim |