The new version of the Exim mail server 4.98

After eight months of development, the release of the Exim mail server 4.98 has been published, which includes accumulated fixes and new features. The project's code is written in C and distributed under the GPLv2+ license. According to a June automated survey of about 400,000 mail servers, Exim holds a share of 59.06% (up from 55.93% a year ago), Postfix is used on 34.68% (down from 37.40%) of mail servers, Sendmail – 3.42% (down from 3.45%), MailEnable – 1.81% (down from 1.86%), MDaemon – 0.37% (down from 0.48%), Microsoft Exchange – 0.17% (down from 0.25%).

Key Changes:

  • A vulnerability (CVE-2024-39929) has been fixed, caused by incorrect parsing of file names in mail attachments. This vulnerability allows bypassing filters that use the $mime_filename variable, enabling the transmission of executable files in attachments despite their being blocked in the settings.
  • In the ACL applicable to data, variables for the DATA command, the condition dkim_status is allowed, enabling the assessment of the verification result via the DKIM (DomainKeys Identified Mail) mechanism.
  • With the dkim_verbose setting enabled, which outputs additional debug information about the operation of DKIM to the log, information about digital signatures is now provided.
  • In the dkim_timestamps option, which controls the inclusion of time information in the signature, the value "0" is permitted to add the current time.
  • In the recipients_max option, which sets the limit on the number of recipients for a single message, the use of substitutions and templates is allowed.
  • When testing expressions using the "exim -be" command, the ability to set tainted values (values obtained externally, for example, set by the message sender) has been provided.
  • Support has been added for processing and logging the event "dns:fail" that occurs when a request to the DNSBL lists fails.
  • Support for searching by incomplete file path has been added in the dsearch lookup blocks ("${lookup {foo/bar} dsearch,key=path {/etc}}").
  • The mailtest utility has been included for checking and diagnosing SMTP connections.
  • Support for the SMTP WELLKNOWN extension has been implemented, allowing the SMTP server to provide public information to the client, such as contact details or verification parameters upon receipt TLS certificate, using the ACME protocol.
  • The use of SQLite3 for internal DB storage has been added, in addition to DBD, NDB, GBDM, and TDB. To use SQLite3, it is necessary to specify "USE_SQLITE = y" and "DBMLIB = -lsqlite3" in the Local/Makefile before building.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster