[CLSA-2023:1688070370] Fix CVE(s): CVE-2021-38371
Type:
security
Severity:
Important
Release date:
2023-06-29 20:26:15 UTC
Description:
* SECURITY UPDATE: Response injection (buffering) during MTA SMTP sending - debian/patches/CVE-2021-38371.patch: Enforce STARTTLS sync point, client side in src/transports/smtp.c - CVE-2021-38371
Updated packages:
  • exim4_4.86.2-2ubuntu2.6+tuxcare.els3_all.deb
    sha:3d3adba60365fa4bbd82e53effaf6c0a683e6989
  • exim4-base_4.86.2-2ubuntu2.6+tuxcare.els3_amd64.deb
    sha:ba06401e99494f58bf1230d93716a49afbf5cb5e
  • exim4-config_4.86.2-2ubuntu2.6+tuxcare.els3_all.deb
    sha:f3a55aaebb5715417e13374df5393038260d3a36
  • exim4-daemon-heavy_4.86.2-2ubuntu2.6+tuxcare.els3_amd64.deb
    sha:58930e76a52aba2216bc03062808d6cf559d7113
  • exim4-daemon-light_4.86.2-2ubuntu2.6+tuxcare.els3_amd64.deb
    sha:30ec1265cdc7455757c094b281985712b0ad7030
  • exim4-dev_4.86.2-2ubuntu2.6+tuxcare.els3_amd64.deb
    sha:56a41488f0643f721ea176721ce15ae724cc833a
  • eximon4_4.86.2-2ubuntu2.6+tuxcare.els3_amd64.deb
    sha:0a331173fef3c987edd7cfadee1bdfc3500811d5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.