[CLSA-2023:1687795531] Fix CVE(s): CVE-2021-38371
Type:
security
Severity:
Important
Release date:
2023-06-26 16:05:35 UTC
Description:
* SECURITY UPDATE: Response injection (buffering) during MTA SMTP sending - debian/patches/CVE-2021-38371.patch: Enforce STARTTLS sync point, client side in src/transports/smtp.c - CVE-2021-38371
Updated packages:
  • exim4_4.90.1-1ubuntu1.10+tuxcare.els1_all.deb
    sha:fd3dce7a5795b5702109804122b032c796e4d293
  • exim4-base_4.90.1-1ubuntu1.10+tuxcare.els1_amd64.deb
    sha:e03cf0a6af5496a74c33be91d2b60c2bc31537eb
  • exim4-config_4.90.1-1ubuntu1.10+tuxcare.els1_all.deb
    sha:3c43536602c3bc9fda066b40e9ad57606810139e
  • exim4-daemon-heavy_4.90.1-1ubuntu1.10+tuxcare.els1_amd64.deb
    sha:ae72072ae3d3af41ca73cae85f3d8556162feed5
  • exim4-daemon-light_4.90.1-1ubuntu1.10+tuxcare.els1_amd64.deb
    sha:144f2d728e268ed5fbb387ad4aae33a4258e850b
  • exim4-dev_4.90.1-1ubuntu1.10+tuxcare.els1_amd64.deb
    sha:c57baeac6c3a7ae81ce9c4118daabb6e6fa10159
  • eximon4_4.90.1-1ubuntu1.10+tuxcare.els1_amd64.deb
    sha:f0a6caa112e721cb6e763aade403516b56e298a6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.