![]() |
|
Message-ID: <Z7ZWBkGnmycxYzGV@jumper.schlittermann.de>
Date: Wed, 19 Feb 2025 23:07:02 +0100
From: Heiko Schlittermann <hs@...marc.schlittermann.de>
To: oss-security <oss-security@...ts.openwall.com>
Subject: Exim: CVE-2025-26794: upcoming security release
CVE-2025-26794
Dear Exim users,
we got a vulnerability report and are going to release a security
release on Friday, Feb 21th, 2025, at 12:00 UTC (coordinated
release date).
Distribution packagers are informed already.
The reported vulnerability is limited to the current Exim version 4.98.
Older versions are not affected.
Please understand that we don't share any further details yet.
The new version 4.98.1 *will* be available
via Git (branch exim-4.98+fixes, tag exim-4.98.1):
https://code.exim.org/exim/exim.git (master repo)
https://code.exim.org/exim/exim/releases/tag/exim-4.98.1
https://github.com/exim/exim.git (mirrored repo)
https://github.com/Exim/exim/releases/tag/exim-4.98.1
as tarball:
https://downloads.exim.org/exim4/
Commits and tarballs are signed by me, with the same key that I'm using
to sign this message.
(In case you're building directly from our master branch: there are no
patches to the master branch yet.)
Thank you for using Exim.
Best regards from Dresden/Germany
Viele Grüße aus Dresden
Heiko Schlittermann
--
SCHLITTERMANN.de ---------------------------- internet & unix support -
Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
gnupg encrypted messages are welcome --------------- key ID: F69376CE -
Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.