New Debian exim4 4.96-15+deb12u7 fixes: This update addresses the following issues: * * A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges. (CVE-2025-30232)
--- mirror/ftp/pool/main/e/exim4/exim4_4.96-15+deb12u6.dsc +++ apt/ucs_5.2-0-errata5.2-1/source/exim4_4.96-15+deb12u7.dsc @@ -1,3 +1,8 @@ +4.96-15+deb12u7 [Sat, 22 Mar 2025 11:25:14 +0100] Andreas Metzler <ametzler@debian.org>: + + * Fix use-after-free (requiring local command-line access) notified by + Trend Micro (ref: ZDI-CAN-26250). CVE-2025-30232 + 4.96-15+deb12u6 [Sat, 28 Sep 2024 16:49:26 +0200] Andreas Metzler <ametzler@debian.org>: * Fix crash in dbmnz when looking up keys with no content. <http://piuparts.knut.univention.de/5.2-1/#6680242235944503169>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-1] 3e35bceaaa Bug #58157: exim4 4.96-15+deb12u7 doc/errata/staging/exim4.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
*** Bug 58156 has been marked as a duplicate of this bug. ***
<https://errata.software-univention.de/#/?erratum=5.2x57>