On välja antud e-posti server Exim 4.97, kuhu on tehtud vajalikud parandused ja lisatud uusi võimalusi. Novembrikuu automatiseeritud küsitluse kohaselt moodustab Eximi osakaal umbes 700 000 e-posti serverist 58,73% (aasta tagasi 60,90%), Postfixi osakaal on 34,86% (32,49%), Sendmail — 3,46% (3,51%), MailEnable — 1,84% (1,91%), MDaemon — 0,40% (0,42%), Microsoft Exchange — 0,19% (0,20%).
Peamised muudatused:
- Käideldud on utiliiti exim_msgdate, et muuta sõnumite identifikaatoreid (message-id) arusaadavaks formaadiks.
- Eksimiga testimise mehhanismi, mis käivitatakse valiku «-be» kasutamisel, on lisatud muutuja seadistamise võimalus.
- Lisatud on sündmus, mis genereeritakse kliendi poolel ja serverile SMTP AUTH autentimise rikka tõrke korral.
- Lisatud on muutuja $sender_helo_verified, mis sisaldab ACL-i «verify = helo» rakendamise tulemust.
- Lisatud on eeldefineeritud makrode tugi elementide, operaatorite, tingimuste ja muutujate avamiseks.
- Tagatud on varajane (enne kasutuselevõttu) SMTP valiku «max_rcpt» avamine.
- OpenSSL-i tls_eccurve valikus on tagatud gruppide nimede nimekirja vastuvõtt.
- Queue handlers can now be launched from a single background process.
- An operator has been added for splitting long header lines.
- A command-line option has been added to output only message IDs in the queue.
- The ${readsocket} operator now allows setting SNI for TLS.
- In the remove_header ACL modifier, it is now permitted to specify regular expressions.
- A $recipients_list variable has been added with a correctly escaped list of recipients.
- For log_selector, a parameter has been implemented to reflect the IDs of incoming connections.
- Five vulnerabilities identified at the end of September have been fixed, three of which (CVE-2023-42115, CVE-2023-42116, CVE-2023-42117) allow remote code execution without authentication on serveril the process's permissions accepting connections on port 25, while the remaining two (CVE-2023-42114 and CVE-2023-42119) can lead to memory content leakage from the process serving network requests.
Allikas: opennet.ru
