===========================



## List details at https://lists.exim.org/mailman/listinfo/exim-announce Exim details at http://www.exim.org/ ##



-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256General release informationThe code fix for this issue has been placed in the projectpublic git repository; the project website will be updatedin due course.CVE ID: CVE-2019-13917OVE ID: OVE-20190718-0006Date: 2019-07-18Credits: Jeremy HarrisVersion(s): 4.85 up to and including 4.92Issue: A local or remote attacker can execute programs with rootprivileges - if you've an unusual configuration. For detailssee below.Coordinated Release Date (CRD) for Exim 4.92.1:Thu Jul 25 10:00:00 UTC 2019Contact: security@exim.orgDetails:A vulnerability was discovered in the "sort" expansion operator:The elements of the list were expanded, giving a possible attackif the list included data supplied by an attacker.If the effective configuration file for exim does not use sortthen the system is trivially declarable as not being vulnerable.Use this command to check: "exim -bP config | grep sort".- --Cheers,Jeremy-----BEGIN PGP SIGNATURE-----iQEzBAEBCAAdFiEEqYbzpr1jd9hzCVjevOWMjOQfMt8FAl05cJMACgkQvOWMjOQfMt+wyAf9GtHba4nfUCmz/juxXwJjfN2R5OF7S1QcA9gRD/2G8F4rf08VBHkdgAaVqLjnHR8RcQzMrVmjTLpZA1zZKy21+LCeQUgAKZksGa8/6AVx3k7JGc/vnqT8QMiE173RTAp9IHh6Y3piYtIbzV3PFlnnRcaRaDSqNJ/c6NWpOzP2IW5mMewMz0n0/cO0Wm02HadUJ+5fKpnjDIicimPi5Jt7V/ECCVr7ecui2IaY4cnAMoglP439cFAM+4BPXighCFfqTg7tLikuSshEQiA/D3rYoXBDpBknfXpmK3eQDX6SUf3XiXPG6OB3X/7oxTjPoxn2MueFxjSvpIlJEeFde535HQ===lGYE-----END PGP SIGNATURE-------