[ubuntu/resolute-updates] exim4 4.99.1-1ubuntu1.5 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Mon Sep 28 14:05:48 UTC 2026
exim4 (4.99.1-1ubuntu1.5) resolute-security; urgency=medium
* SECURITY UPDATE: out-of-bounds write when used with attacker-controlled
proxy
- debian/patches/CVE-2026-94054.patch: Proxy-protocol: Fix OOB read in
src/proxy.c.
- CVE-2026-94054
* SECURITY UPDATE: use-after-free with non-default TLS settings
- debian/patches/CVE-2026-94055.patch: GnuTLS: fix early-close under Early
Banner in src/tls-gnu.c.
- CVE-2026-94055
* SECURITY UPDATE: uninitialized stack leak when used with attacker-
controlled proxy
- debian/patches/CVE-2026-94056.patch: Proxy-protocol: account for short
received V2 header in src/proxy.c.
- CVE-2026-94056
* SECURITY UPDATE: SMTP smuggling via crafted data
- debian/patches/CVE-2026-94057.patch: Avoid more "SMTP smuggling" attack
types in src/receive.c.
- CVE-2026-94057
Date: 2026-09-23 12:21:31.860763+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/exim4/4.99.1-1ubuntu1.5
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list