Exim Mail Server Developers Administrators have been informed of the intention to release an update 4.92.1 on July 25, which will address a critical vulnerability (CVE-2019-13917) that allows remote code execution with root privileges under certain specific configuration settings.
Details about the issue have not yet been disclosed, and all mail server administrators are advised to prepare for the installation of an emergency update on July 25. On that day, coordinated updates for packages with Exim will be released in major distributions. The risk of exploitation of the vulnerability is noted as low, as it does not manifest in the default configuration, both in the base Exim installation and in the Debian package.
Source: opennet.ru
