The Exim developers have announced the discovery of a vulnerability and an upcoming release with an update that addresses it. It is noted that the risk of exploitation is quite low, as it requires a specific configuration. Details are not yet disclosed, except that exploitation is possible both locally and remotely.
The update will be released on July 25, 2019, at which time all details will also be disclosed. Currently, all relevant versions are potentially vulnerable, but neither the configuration proposal from the developers nor the package in Debian is under threat.
Source: linux.org.ru
