Skip to content

[Deepin Integration]~[v25-Release] feat: update exim4 to 4.98.2-1+deb13u4 by deepin-community-bot[bot]@deepin-community/exim4 by deepin-community-ci-bot[bot] #13764

Description

@deepin-bot

Package information | 软件包信息

包名 版本
exim4 4.98.2-1+deb13u4

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-4414:/community/testing/ ./

Changelog | 更新信息

exim4 (4.98.2-1+deb13u4) trixie-security; urgency=high

  • Fix two local privilege escalation issues.
    EXIM-Security-2026-06-22.1 (GCVE-25-2026-07-45-1)
    Using command-line arguments intended for transferring queue-name
    through an Exim execution chain, files outside the spool area can be
    accessed. This can be used for a privilege escalation. CVE-2026-66140
    EXIM-Security-2026-06-22.3 (GCVE-25-2026-07-45-3)
    A local user having a .forward file can use a string-expansion there.
    With certain Exim configurations this can be used as a privilege
    escalation. CVE-2026-66141

Metadata

Metadata

Type

No type

Projects

Status
In progress

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions