Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Yu5+6SlKH6n6afZv@gentoo.org>
Date: Sat, 6 Aug 2022 09:47:05 -0500
From: John Helmert III <ajak@...too.org>
To: oss-security@...ts.openwall.com
Subject: Re: Exim 4.95 invalid free

Hi, please keep in mind the list content guidelines:

"At least the most essential part of your message (e.g., vulnerability detail and/or exploit) should be directly included in the message itself (and in plain text), rather than only included by reference to an external resource. Posting links to relevant external resources as well is acceptable, but posting only links is not. Your message should remain valuable even with all of the external resources gone."

Do you have any upstream references or commits of the fix?

On Sat, Aug 06, 2022 at 12:06:36PM +0300, Evgeny Legerov wrote:
> Hi,
> 
> 
> The issue has been silently fixed in Exim 4.96 - 
> https://github.com/ivd38/exim_invalid_free
> 
> 
> 
> regards,
> 
> -e
> 

Download attachment "signature.asc" of type "application/pgp-signature" (229 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.