USN-4934-2: Exim vulnerabilities
6 May 2021
Several security issues were fixed in Exim.
Releases
Packages
- exim4 - Exim is a mail transport agent
Details
USN-4934-1 fixed several vulnerabilities in Exim. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
CVE-2020-28026 only affected Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Exim contained multiple security issues. An attacker
could use these issues to cause a denial of service, execute arbitrary
code remotely, obtain sensitive information, or escalate local privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
exim4-base
-
4.86.2-2ubuntu2.6+esm1
Available with Ubuntu Pro
-
exim4-daemon-heavy
-
4.86.2-2ubuntu2.6+esm1
Available with Ubuntu Pro
-
exim4-daemon-light
-
4.86.2-2ubuntu2.6+esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
exim4-base
-
4.82-3ubuntu2.4+esm3
Available with Ubuntu Pro
-
exim4-daemon-heavy
-
4.82-3ubuntu2.4+esm3
Available with Ubuntu Pro
-
exim4-daemon-light
-
4.82-3ubuntu2.4+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
Related notices
- USN-4934-1: exim4-dev, exim4-daemon-heavy, exim4-daemon-light, exim4-base, exim4, eximon4, exim4-config