You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Deepin Integration]~[v25-Release] feat: update exim4 to 4.98.2-1+deb13u4 by deepin-community-bot[bot]@deepin-community/exim4 by deepin-community-ci-bot[bot] #13764
Fix two local privilege escalation issues.
EXIM-Security-2026-06-22.1 (GCVE-25-2026-07-45-1)
Using command-line arguments intended for transferring queue-name
through an Exim execution chain, files outside the spool area can be
accessed. This can be used for a privilege escalation. CVE-2026-66140
EXIM-Security-2026-06-22.3 (GCVE-25-2026-07-45-3)
A local user having a .forward file can use a string-expansion there.
With certain Exim configurations this can be used as a privilege
escalation. CVE-2026-66141
Package information | 软件包信息
Package repository address | 软件包仓库地址
Changelog | 更新信息
exim4 (4.98.2-1+deb13u4) trixie-security; urgency=high
EXIM-Security-2026-06-22.1 (GCVE-25-2026-07-45-1)
Using command-line arguments intended for transferring queue-name
through an Exim execution chain, files outside the spool area can be
accessed. This can be used for a privilege escalation. CVE-2026-66140
EXIM-Security-2026-06-22.3 (GCVE-25-2026-07-45-3)
A local user having a .forward file can use a string-expansion there.
With certain Exim configurations this can be used as a privilege
escalation. CVE-2026-66141