- update to exim 4.92.3

* CVE-2019-16928: fix against Heap-based buffer overflow in string_vformat,
    remote code execution seems to be possible

OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=217
This commit is contained in:
Peter Poeml 2019-09-30 15:41:24 +00:00 committed by Git OBS Bridge
parent 64cccf5ce7
commit 4f052de71e
6 changed files with 24 additions and 17 deletions

View File

@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:557f97c3f75c19a2e7da8511a8b94c28b39a5d5206948be5ceac96c75a2eccf6
size 1933063

View File

@ -1,11 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQEzBAABCgAdFiEE0L/WueylaUpvFJ3Or0zGdqa2wUIFAl1uO6cACgkQr0zGdqa2
wUJnoAgAzQvg1QmtCxAO/Qva1Coc8K9wTQDIYRhYDPSRX6b6jJsIzXSzgK5cqj3E
Mfly/uvPKFBshKi2YxcXl5p1ILfHGP+XYEK+M7X+XEBRBW8odSgMCI9yh79acx3z
dctuTHbTja+6vUToDaKl76v2ZDP9Dfp9yfY8d1OPDTsyAc8QdTcQbzWRl1CIo+cI
QgDZ0LTPoPLu/cGZ+3MKhfPoyYXzUVhAWTHRZgdNKnSgTksmgS05o7Lulyjrcggz
Pis4SyqleyqpnT5yfVYP/W48qMlnQmvWywjWQ5vD3sxodCjh89HEU/2ge2N+qAjz
iC1ytDM0+K+jMbtnPqsFY96dYjP00w==
=BWrd
-----END PGP SIGNATURE-----

3
exim-4.92.3.tar.bz2 Normal file
View File

@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:29966aab50523cd7b7f90a0788c79a16b75181513115a61302ce0f7a93041034
size 1933605

11
exim-4.92.3.tar.bz2.asc Normal file
View File

@ -0,0 +1,11 @@
-----BEGIN PGP SIGNATURE-----
iQEzBAABCgAdFiEE0L/WueylaUpvFJ3Or0zGdqa2wUIFAl2P4GMACgkQr0zGdqa2
wUJlLAgAyPIQP/rZAp/BH6MAvITmmcSFtNEBwHOGYOmvnnr9/GVQcG8zG0OTu0Jl
wzJvvpKcW7ADf7boMEPWlbk7HV08Ek/T7PRpgE8AcikpuIvBMeZ1FTGUOZqUW7D2
1dH1UxYF8mqKnmK0Q63v8X3y1ujZPwMwODc0QGo+nQRwxq7A+qaTOAryy3Tcxnh1
SWI/zay4Dn2PSdbzmgHhhrPR3yha4b0gTXvkm1DUKmWT24UcMQMEsd2JMq1Bx9j2
4r4LzkxewYkVztLw6QRozxN3KIHmZewCNNTnhZhD/Sq5fQPDE5uN52CoOljpWrhQ
+ChJP8PSfXVtGREGxRqpOxBY+xnG7Q==
=CvIA
-----END PGP SIGNATURE-----

View File

@ -1,3 +1,10 @@
-------------------------------------------------------------------
Mon Sep 30 15:39:54 UTC 2019 - poeml@cmdline.net
- update to exim 4.92.3
* CVE-2019-16928: fix against Heap-based buffer overflow in string_vformat,
remote code execution seems to be possible
-------------------------------------------------------------------
Sat Sep 7 18:22:08 UTC 2019 - poeml@cmdline.net

View File

@ -1,7 +1,7 @@
#
# spec file for package exim
#
# Copyright (c) 2019 SUSE LINUX GmbH, Nuernberg, Germany.
# Copyright (c) 2019 SUSE LINUX Products GmbH, Nuernberg, Germany.
#
# All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed
@ -12,7 +12,7 @@
# license that conforms to the Open Source Definition (Version 1.9)
# published by the Open Source Initiative.
# Please submit bugfixes or comments via https://bugs.opensuse.org/
# Please submit bugfixes or comments via http://bugs.opensuse.org/
#
@ -72,7 +72,7 @@ Requires(pre): group(mail)
%endif
Requires(pre): fileutils textutils
%endif
Version: 4.92.2
Version: 4.92.3
Release: 0
%if %{with_mysql}
BuildRequires: mysql-devel