Exim 4.100.1 fixes four security vulnerabilities, including high-severity Proxy Protocol and GnuTLS use-after-free flaws and a medium-severity SMTP smuggling issue that could let attackers alter submitted email content. The security release was announced on September 18, 2026, and affects Exim deployments running versions as old as 4.83 in some configurations. Administrators using impacted versions are strongly advised to upgrade to Exim 4.100.1. One of the most serious issues, tracked as GCVE-25-2026-09-50-1, affects Exim installations configured to use Proxy Protocol version 1. The flaw is an out-of-bounds write and heap corruption issue. A remote attacker could trigger a read of roughly 230 bytes beyond the end of a heap...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!