Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <5f0712ff-44b4-cef2-1276-424c1cfa094e@vulndisco.cc>
Date: Sat, 6 Aug 2022 19:40:49 +0300
From: Evgeny Legerov <admin@...ndisco.cc>
To: oss-security@...ts.openwall.com
Subject: Re: Exim 4.95 invalid free

My bad.

Fix is here 
https://github.com/Exim/exim/commit/51be321b27825c01829dffd90f11bfff256f7e42

On 06.08.2022 17:47, John Helmert III wrote:
> Hi, please keep in mind the list content guidelines:
>
> "At least the most essential part of your message (e.g., vulnerability detail and/or exploit) should be directly included in the message itself (and in plain text), rather than only included by reference to an external resource. Posting links to relevant external resources as well is acceptable, but posting only links is not. Your message should remain valuable even with all of the external resources gone."
>
> Do you have any upstream references or commits of the fix?
>
> On Sat, Aug 06, 2022 at 12:06:36PM +0300, Evgeny Legerov wrote:
>> Hi,
>>
>>
>> The issue has been silently fixed in Exim 4.96 -
>> https://github.com/ivd38/exim_invalid_free
>>
>>
>>
>> regards,
>>
>> -e
>>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.