Opened 7 years ago

Closed 7 years ago

#8684 closed enhancement (fixed)

exim-4.88 (CVE-2016-9963)

Reported by: Douglas R. Reno Owned by: Pierre Labastie
Priority: highest Milestone: 8.0
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description

New critical security version

Deals with Information Disclosure

  - Fix CVE-2016-9963 - Info leak from DKIM.  When signing DKIM, if
      either LMTP or PRDR was used for delivery, the key could appear in
      logs.  Additionally, if the experimental feature "DSN_INFO" was used,
      it could appear in DSN messages (and be sent offsite).

Change History (2)

comment:1 by Pierre Labastie, 7 years ago

Owner: changed from blfs-book@… to Pierre Labastie
Status: newassigned

comment:2 by Pierre Labastie, 7 years ago

Resolution: fixed
Status: assignedclosed

Fixed at r18125

Note: See TracTickets for help on using tickets.