oss-sec mailing list archives
CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead
From: Heiko Schlittermann <hs () nodmarc schlittermann de>
Date: Mon, 22 Jul 2019 12:00:13 +0200
*** Note: EMBARGO is still in effect until July 25th, 10:00 UTC. ***
*** Distros must not publish any detail nor release updates yet. ***
CVE ID: CVE-2019-13917
OVE ID: OVE-20190718-0006
Date: 2019-07-18
Credits: Jeremy Harris
Version(s): 4.85 up to and including 4.92
Issue: A local or remote attacker can execute programs with root
privileges - if you've an unusual configuration. For details
see below.
Coordinated Release Date (CRD) for Exim 4.92.1:
Thu Jul 25 10:00:00 UTC 2019
Contact: security () exim org
This is a *heads-up* notice about the upcoming release.
You may plan your availability and schedule an update of the Exim
packages supplied by your distribution or build the new release from the
source, once the release goes public on CRD.
Details
=======
We discovered a vulnerability. We consider the risk of an exploit as
low, you need to have a fairly unusual runtime configuration. Neither
our default runtime configuration nor the runtime configuration shipped
by the Debian distribution is vulnerable.
The vulnerability is exploitable either remotely or locally and could
be used to execute other programs with root privilege.
More details and fixes are not yet public, but will be made public on
CRD, July 25th.
Timeline
========
t0: Thu Jul 18 2019
- this notice to distros () vs openwall org and exim-maintainers () exim org
- open limited access to our security Git repo. See below.
t0+~4d: Mon Jul 22 10:00:00 UTC 2019 [NOW]
- heads-up notice to oss-security () lists openwall com,
exim-users () exim org, and exim-announce () exim org
t0+~7d: Thu Jul 25 10:00:00 UTC 2019
- Coordinated relase date
- publish the patches in our official and public Git repositories
and the packages on our FTP server.
Downloads available starting at CRD
====================================
For release tarballs (exim-4.92.1):
http://ftp.exim.org/pub/exim/exim4/
The package files are signed with my GPG key.
For the full Git repo:
https://git.exim.org/exim.git
https://github.com/Exim/exim [mirror of the above]
- tag exim-4.92.1
- branch exim-4.92.1+fixes
The tagged commit is the officially released version. The tag is signed
with my GPG key. The +fixes branch isn't officially maintained, but
contains useful patches *and* the security fix. The relevant commit is
signed with my GPG key. The old exim-4.92+fixes branch is being functionally
replaced by the new exim-4.92.1+fixes branch.
Best regards from Dresden/Germany
Viele Grüße aus Dresden
Heiko Schlittermann
--
SCHLITTERMANN.de ---------------------------- internet & unix support -
Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
gnupg encrypted messages are welcome --------------- key ID: F69376CE -
! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -
Attachment:
signature.asc
Description:
Current thread:
- CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Heiko Schlittermann (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Mikhail Klementev (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Stuart Henderson (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Mikhail Klementev (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Solar Designer (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Amos Jeffries (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Ian Zimmerman (Jul 22)
- Security release pre-announcement messages Douglas Bagnall (Jul 24)
- Re: Security release pre-announcement messages Stiepan (Jul 26)
- Re: Security release pre-announcement messages Greg KH (Jul 26)
- Re: Security release pre-announcement messages Greg KH (Jul 26)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Stuart Henderson (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Mikhail Klementev (Jul 22)
