#22537 closed enhancement (fixed)
exim-4.99.1
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (8)
comment:1 by , 10 months ago
| Priority: | normal → high |
|---|
comment:2 by , 10 months ago
Fixes CVE-2025-67896 (Medium): Remote heap corruption.
From testing, remote code execution couldn't be achieved but doesn't mean it's not impossible.
comment:3 by , 10 months ago
| Priority: | high → elevated |
|---|
comment:4 by , 10 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:5 by , 10 months ago
The initial report can be found here: https://www.exim.org/static/doc/security/EXIM-Security-2025-12-09.1/report.txt
Note that it came from an employee from NIST.
From the release announcement:
This is a security release. It fixes CVE-2025-67896 (aka EXIM-Security-2025-12-09.1), which was introduced with 4.99. Older Exim versions may or may not be vulnerable and are not activly maintained anymore by the Exim maintainers. (To the best of our knowledge, 4.98.1 should be safe.) Configurations using SQlite for lookups and hintdb were vulnerable. Details: https://code.exim.org/exim/exim/src/branch/exim-4.99+fixes/doc/doc-txt/exim-security-2025-12-09.1/report.txt
comment:6 by , 10 months ago
| Priority: | elevated → high |
|---|
https://nvd.nist.gov/vuln/detail/CVE-2025-67896 shows that the CVE is rated as High
comment:7 by , 10 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at ac45ddd76115a1ed66842b04a49ce2a067aff0f4
SA-12.4-062 issued
Note:
See TracTickets
for help on using tickets.

This is a security release. I'll give more details tomorrow once I get sleep, unless someone else documents the security issues here before I do.