This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

EXIM Vuln. - any news?

Hi,

anyone at Sophos can comment on the EXIM vulns, for instance as described here? https://www.heise.de/news/Jetzt-patchen-Kritische-Root-Luecken-bedrohen-Exim-Mail-Server-6036724.html

Thanks

Joerg



This thread was automatically locked due to age.
Parents
  • We are working as fast as we can (almost 24 hours a day) to get the exim patches out to UTM customers. Unfortunately after integrating the exim patches, we need to do quite a bit of testing (both on email & up2date) to ensure the patches don't introduce any new issues, which is what's taking time. 

    We are still aiming to release updates to both UTM 9.705 & 9.706 this week. 

Reply
  • We are working as fast as we can (almost 24 hours a day) to get the exim patches out to UTM customers. Unfortunately after integrating the exim patches, we need to do quite a bit of testing (both on email & up2date) to ensure the patches don't introduce any new issues, which is what's taking time. 

    We are still aiming to release updates to both UTM 9.705 & 9.706 this week. 

Children
  • Hi bobbylam, i appreciate your response here. But why is there a workaround for XG and not SG. I think mabye Sophos has wrong priorities, not just XG over SG, but developing a patch for Days (weeks?) when there is no workaround like for the XG (IPS, manual fix, stopping the Exploit with disabling other Bugs first, …)

    i know i do not know much about patching and developing Firewalls, but for Firewalls security is essential and can not wait days (again, maybe weeks? We will see)…

  • SG & XG do have different architectures so workarounds applicable to one is not always applicable to another. We are not prioritizing XG over SG on this issue, but each product does require different amount of work & testing to get these patches released. 

    As I said we're working as quickly as we can to get these patches out for UTM safely to ensure customers do not have to wait for weeks.