At the beginning of September, the developers of the Exim mail server notified users about a critical vulnerability (CVE-2019-15846) that allows a local or remote attacker to execute their code on the server with root privileges. Exim users were advised to install an unplanned update 4.92.2.
On September 29, another emergency release of Exim 4.92.3 was published to address yet another critical vulnerability (CVE-2019-16928) that allows remote code execution on the server. The vulnerability manifests after privilege escalation and is limited to code execution with the privileges of the unprivileged user under which the incoming message handler runs.
Users are strongly advised to install the update urgently. Fixes have been released for Ubuntu 19.04, Arch Linux, FreeBSD, Debian 10, and Fedora. In RHEL and CentOS, Exim is not included in the standard package repository. In SUSE and openSUSE, the Exim 4.88 branch is used.
Source: linux.org.ru
