This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Info urgent EXIM vulnerability

Hi forum,

any intel or comment from Sophos regarding this?  https://www.zerodayinitiative.com/advisories/ZDI-23-1469/

Is SG affected? 

Thanks

Joerg



This thread was automatically locked due to age.
Parents
  • Hi,

    some updates from the exim maintainers https://seclists.org/oss-sec/2023/q3/254

    "Fixes are available in a protected repository and are ready to be applied by the distribution maintainers ..."

    bye Josef

    BERGMANN engineering & consulting GmbH, Wien/Austria

  • Hi,

    It seems the hotfix has been deployed?

    Can you confirm that the hotfix affects the exim vulnerability?

    DEBUG     2023-10-04 14:31:12Z [2862]: --pkg_sysupdate_version = 3
    DEBUG     2023-10-04 14:36:53Z [4426]: --pkg_sysupdate_version = 3
    DEBUG     2023-10-04 14:38:39Z [6723]: --pkg_sysupdate_version = 4
    DEBUG     2023-10-04 15:01:10Z [14394]: --pkg_sysupdate_version = 4
    DEBUG     2023-10-04 15:06:54Z [15946]: --pkg_sysupdate_version = 4

    BR Gerd

     

Reply
  • Hi,

    It seems the hotfix has been deployed?

    Can you confirm that the hotfix affects the exim vulnerability?

    DEBUG     2023-10-04 14:31:12Z [2862]: --pkg_sysupdate_version = 3
    DEBUG     2023-10-04 14:36:53Z [4426]: --pkg_sysupdate_version = 3
    DEBUG     2023-10-04 14:38:39Z [6723]: --pkg_sysupdate_version = 4
    DEBUG     2023-10-04 15:01:10Z [14394]: --pkg_sysupdate_version = 4
    DEBUG     2023-10-04 15:06:54Z [15946]: --pkg_sysupdate_version = 4

    BR Gerd

     

Children