Opened 10 months ago

Closed 10 months ago

Last modified 8 months ago

#22537 closed enhancement (fixed)

exim-4.99.1

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (8)

comment:1 by zeckma, 10 months ago

Priority: normal → high

This is a security release. I'll give more details tomorrow once I get sleep, unless someone else documents the security issues here before I do.

comment:2 by zeckma, 10 months ago

Fixes CVE-2025-67896 (Medium): Remote heap corruption.

From testing, remote code execution couldn't be achieved but doesn't mean it's not impossible.

comment:3 by zeckma, 10 months ago

Priority: high → elevated

comment:4 by Douglas R. Reno, 10 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:5 by Douglas R. Reno, 10 months ago

The initial report can be found here: ​https://www.exim.org/static/doc/security/EXIM-Security-2025-12-09.1/report.txt

Note that it came from an employee from NIST.

From the release announcement:

This is a security release. It fixes CVE-2025-67896 (aka
EXIM-Security-2025-12-09.1), which was introduced with 4.99. Older Exim
versions may or may not be vulnerable and are not activly maintained
anymore by the Exim maintainers. (To the best of our knowledge, 4.98.1
should be safe.)

Configurations using SQlite for lookups and hintdb were vulnerable.

Details: https://code.exim.org/exim/exim/src/branch/exim-4.99+fixes/doc/doc-txt/exim-security-2025-12-09.1/report.txt

comment:6 by Douglas R. Reno, 10 months ago

Priority: elevated → high

​https://nvd.nist.gov/vuln/detail/CVE-2025-67896 shows that the CVE is rated as High

comment:7 by Douglas R. Reno, 10 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at ac45ddd76115a1ed66842b04a49ce2a067aff0f4

SA-12.4-062 issued

comment:8 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.