First published: Mon Jul 08 2024(Updated: )
It was discovered that Exim did not enforce STARTTLS sync point on client side. An attacker could possibly use this issue to perform response injection during MTA SMTP sending.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/exim4 | <4.93-13ubuntu1.11 | 4.93-13ubuntu1.11 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/exim4-base | <4.93-13ubuntu1.11 | 4.93-13ubuntu1.11 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/eximon4 | <4.93-13ubuntu1.11 | 4.93-13ubuntu1.11 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/exim4 | <4.90.1-1ubuntu1.10+esm4 | 4.90.1-1ubuntu1.10+esm4 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/exim4-base | <4.90.1-1ubuntu1.10+esm4 | 4.90.1-1ubuntu1.10+esm4 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/eximon4 | <4.90.1-1ubuntu1.10+esm4 | 4.90.1-1ubuntu1.10+esm4 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/exim4 | <4.86.2-2ubuntu2.6+esm7 | 4.86.2-2ubuntu2.6+esm7 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/exim4-base | <4.86.2-2ubuntu2.6+esm7 | 4.86.2-2ubuntu2.6+esm7 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/eximon4 | <4.86.2-2ubuntu2.6+esm7 | 4.86.2-2ubuntu2.6+esm7 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/exim4 | <4.82-3ubuntu2.4+esm8 | 4.82-3ubuntu2.4+esm8 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/exim4-base | <4.82-3ubuntu2.4+esm8 | 4.82-3ubuntu2.4+esm8 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/eximon4 | <4.82-3ubuntu2.4+esm8 | 4.82-3ubuntu2.4+esm8 |
Ubuntu Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.