Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:0721-1

Опубликовано: 11 мар. 2016
Источник: suse-cvrf

Описание

Security update for exim

This update to exim 4.86.2 fixes the following issues:

  • CVE-2016-1531: local privilege escalation for set-uid root exim when using 'perl_startup' (boo#968844)

Important: Exim now cleans the complete execution environment by default. This affects Exim and subprocesses such as transports calling other programs. The following new options are supported to adjust this behaviour:

  • keep_environment
  • add_environment A warning will be printed upon startup if none of these are configured.

Also includes upstream changes, improvements and bug fixes:

  • Support for using the system standard CA bundle.
  • New expansion items $config_file, $config_dir, containing the file and directory name of the main configuration file. Also $exim_version.
  • New 'malware=' support for Avast.
  • New 'spam=' variant option for Rspamd.
  • Assorted options on malware= and spam= scanners.
  • A commandline option to write a comment into the logfile.
  • A logging option for slow DNS lookups.
  • New ${env {}} expansion.
  • A non-SMTP authenticator using information from TLS client certificates.
  • Main option 'tls_eccurve' for selecting an Elliptic Curve for TLS.
  • Main option 'dns_trust_aa' for trusting your local nameserver at the same level as DNSSEC.

Список пакетов

openSUSE Leap 42.1
exim-4.86.2-8.1
eximon-4.86.2-8.1
eximstats-html-4.86.2-8.1

Описание

Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.


Затронутые продукты
openSUSE Leap 42.1:exim-4.86.2-8.1
openSUSE Leap 42.1:eximon-4.86.2-8.1
openSUSE Leap 42.1:eximstats-html-4.86.2-8.1

Ссылки
Уязвимость openSUSE-SU-2016:0721-1