[exim] Re: Exim Zero Day?

Top Page
Delete this message
Reply to this message
Author: Christof Meerwald
Date:  
To: Some Guy via Exim-users, Some Guy
Subject: [exim] Re: Exim Zero Day?
On Fri, 29 Sep 2023 15:17:05 +0000, Some Guy via Exim-users wrote:
> Hi, I'm running an appliance which includes an Exim MTA and now I'm wondering, if I should be worried because of the RCE with CVSS 9.8 described at the Zero Day Initiative homepage here:
>
> https://www.zerodayinitiative.com/advisories/ZDI-23-1469/


My understanding (so far, after looking a bit into what information is
publically available about it) is that it heavily depends on the
actual configuration and will probably only affect a tiny percentage
of servers.


Christof

--

https://cmeerw.org                             sip:cmeerw at cmeerw.org
mailto:cmeerw at cmeerw.org                   xmpp:cmeerw at cmeerw.org


--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-users.lists.exim.org/
## unsubscribe (doesn't require an account):
## exim-users-unsubscribe@???
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/