From 221a1e1a2f9c7ff9f77e5b8bb7241d9d3bcd9e7e7bfeef574a5718ff8e0ade88 Mon Sep 17 00:00:00 2001 From: Peter Poeml Date: Sat, 7 Sep 2019 18:25:29 +0000 Subject: [PATCH 1/2] - update to exim 4.92.2 * CVE-2019-15846: fix against remote attackers executing arbitrary code as root via a trailing backslash OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=214 --- exim-4.92.1.tar.bz2 | 3 --- exim-4.92.1.tar.bz2.asc | 11 ----------- exim-4.92.2.tar.bz2 | 3 +++ exim-4.92.2.tar.bz2.asc | 11 +++++++++++ exim.changes | 7 +++++++ exim.spec | 6 +++--- 6 files changed, 24 insertions(+), 17 deletions(-) delete mode 100644 exim-4.92.1.tar.bz2 delete mode 100644 exim-4.92.1.tar.bz2.asc create mode 100644 exim-4.92.2.tar.bz2 create mode 100644 exim-4.92.2.tar.bz2.asc diff --git a/exim-4.92.1.tar.bz2 b/exim-4.92.1.tar.bz2 deleted file mode 100644 index f47898b..0000000 --- a/exim-4.92.1.tar.bz2 +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:b755658ab08cdabca7aaeab25f64cfe4f8d1a0e1998d9750e4bd8cff5faf5f8c -size 1927542 diff --git a/exim-4.92.1.tar.bz2.asc b/exim-4.92.1.tar.bz2.asc deleted file mode 100644 index 04d6d6f..0000000 --- a/exim-4.92.1.tar.bz2.asc +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQEzBAABCgAdFiEE0L/WueylaUpvFJ3Or0zGdqa2wUIFAl0wxWwACgkQr0zGdqa2 -wULwQQgAwivO0tydQLv48NmQ7uJ9Iu6/uLLTFIIuv8sRMHpdtqzv1vuQagOvjhAp -zlSLBL7C5Wovunlof2i9aZm5fvQ7MFD0mABXAkTt5bfAn1X0qgqUCc8/iWYWbGIX -58kVrOQeDPRZKf+Fsm7h/3wS5s4s1uQBjgemyjHkXxeIdb75j+5kS5TeriTxHoLg -rZvHbOoZf1LykNd0JyKahLIF8LukTZA32Jdd5P426oJ6HsT9vtTqwfSQGy2ThYqP -UKIVsny78VM05h2BelMwK44qTpWbNhAK9u58vwNMECjahGvIhIHQk4rES3nErDsf -F1qhEDC4rkoLZpungK6xbrVoyFqtWQ== -=5R4g ------END PGP SIGNATURE----- diff --git a/exim-4.92.2.tar.bz2 b/exim-4.92.2.tar.bz2 new file mode 100644 index 0000000..f2433aa --- /dev/null +++ b/exim-4.92.2.tar.bz2 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:557f97c3f75c19a2e7da8511a8b94c28b39a5d5206948be5ceac96c75a2eccf6 +size 1933063 diff --git a/exim-4.92.2.tar.bz2.asc b/exim-4.92.2.tar.bz2.asc new file mode 100644 index 0000000..d9b5a8e --- /dev/null +++ b/exim-4.92.2.tar.bz2.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCgAdFiEE0L/WueylaUpvFJ3Or0zGdqa2wUIFAl1uO6cACgkQr0zGdqa2 +wUJnoAgAzQvg1QmtCxAO/Qva1Coc8K9wTQDIYRhYDPSRX6b6jJsIzXSzgK5cqj3E +Mfly/uvPKFBshKi2YxcXl5p1ILfHGP+XYEK+M7X+XEBRBW8odSgMCI9yh79acx3z +dctuTHbTja+6vUToDaKl76v2ZDP9Dfp9yfY8d1OPDTsyAc8QdTcQbzWRl1CIo+cI +QgDZ0LTPoPLu/cGZ+3MKhfPoyYXzUVhAWTHRZgdNKnSgTksmgS05o7Lulyjrcggz +Pis4SyqleyqpnT5yfVYP/W48qMlnQmvWywjWQ5vD3sxodCjh89HEU/2ge2N+qAjz +iC1ytDM0+K+jMbtnPqsFY96dYjP00w== +=BWrd +-----END PGP SIGNATURE----- diff --git a/exim.changes b/exim.changes index 09b872a..6ea2240 100644 --- a/exim.changes +++ b/exim.changes @@ -1,3 +1,10 @@ +------------------------------------------------------------------- +Sat Sep 7 18:22:08 UTC 2019 - poeml@cmdline.net + +- update to exim 4.92.2 + * CVE-2019-15846: fix against remote attackers executing arbitrary code as + root via a trailing backslash + Thu Jul 25 13:43:52 UTC 2019 - alex - update to exim 4.92.1 diff --git a/exim.spec b/exim.spec index 6bd415d..aff4f36 100644 --- a/exim.spec +++ b/exim.spec @@ -1,7 +1,7 @@ # # spec file for package exim # -# Copyright (c) 2019 SUSE LINUX GmbH, Nuernberg, Germany. +# Copyright (c) 2019 SUSE LINUX Products GmbH, Nuernberg, Germany. # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -12,7 +12,7 @@ # license that conforms to the Open Source Definition (Version 1.9) # published by the Open Source Initiative. -# Please submit bugfixes or comments via https://bugs.opensuse.org/ +# Please submit bugfixes or comments via http://bugs.opensuse.org/ # @@ -72,7 +72,7 @@ Requires(pre): group(mail) %endif Requires(pre): fileutils textutils %endif -Version: 4.92.1 +Version: 4.92.2 Release: 0 %if %{with_mysql} BuildRequires: mysql-devel From 64cccf5ce77f8983baece7eb26600abdb5afff98207a5b430d9ae1b83a400e4d Mon Sep 17 00:00:00 2001 From: Dirk Mueller Date: Wed, 11 Sep 2019 13:54:59 +0000 Subject: [PATCH 2/2] OBS-URL: https://build.opensuse.org/package/show/server:mail/exim?expand=0&rev=215 --- exim.changes | 1 + exim.spec | 4 ++-- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/exim.changes b/exim.changes index 6ea2240..f1a5d13 100644 --- a/exim.changes +++ b/exim.changes @@ -5,6 +5,7 @@ Sat Sep 7 18:22:08 UTC 2019 - poeml@cmdline.net * CVE-2019-15846: fix against remote attackers executing arbitrary code as root via a trailing backslash +------------------------------------------------------------------- Thu Jul 25 13:43:52 UTC 2019 - alex - update to exim 4.92.1 diff --git a/exim.spec b/exim.spec index aff4f36..176f889 100644 --- a/exim.spec +++ b/exim.spec @@ -1,7 +1,7 @@ # # spec file for package exim # -# Copyright (c) 2019 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2019 SUSE LINUX GmbH, Nuernberg, Germany. # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -12,7 +12,7 @@ # license that conforms to the Open Source Definition (Version 1.9) # published by the Open Source Initiative. -# Please submit bugfixes or comments via http://bugs.opensuse.org/ +# Please submit bugfixes or comments via https://bugs.opensuse.org/ #