Debian Package Tracker
Register | Log in
Subscribe

exim4

metapackage to ease Exim MTA (v4) installation

Choose email to subscribe with

general
  • source: exim4 (main)
  • version: 4.99.2-1
  • maintainer: Exim4 Maintainers (archive) (DMD)
  • uploaders: Andreas Metzler [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.94.2-7+deb11u3
  • o-o-sec: 4.94.2-7+deb11u4
  • o-o-p-u: 4.94.2-7+deb11u3
  • oldstable: 4.96-15+deb12u7
  • old-sec: 4.96-15+deb12u7
  • old-bpo: 4.98.2-1~bpo12+1
  • old-p-u: 4.96-15+deb12u8
  • stable: 4.98.2-1
  • stable-bpo: 4.99.2-1~bpo13+1
  • stable-p-u: 4.98.2-1+deb13u1
  • testing: 4.99.2-1
  • unstable: 4.99.2-1
versioned links
  • 4.94.2-7+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.94.2-7+deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.96-15+deb12u7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.96-15+deb12u8: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.98.2-1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.98.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.98.2-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.99.1-1~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.99.2-1~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.99.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • exim4 (64 bugs: 0, 33, 31, 0)
  • exim4-base (18 bugs: 0, 10, 8, 0)
  • exim4-config (73 bugs: 0, 30, 43, 0)
  • exim4-daemon-heavy (16 bugs: 0, 9, 7, 0)
  • exim4-daemon-light (4 bugs: 0, 3, 1, 0)
  • exim4-daemon-mod
  • exim4-dev
  • exim4-mod-cyrus-sasl
  • exim4-mod-ldap
  • exim4-mod-mysql
  • exim4-mod-pam
  • exim4-mod-perl
  • exim4-mod-postgresql
  • exim4-mod-spf
  • eximon4
action needed
2 security issues in bullseye high

There are 2 open security issues in bullseye.

2 important issues:
  • CVE-2026-40686: In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
  • CVE-2026-40687: In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
Created: 2026-04-30 Last update: 2026-05-06 13:30
1 bug tagged help in the BTS normal
The BTS contains 1 bug tagged help, please consider helping the maintainer in dealing with it.
Created: 2019-03-21 Last update: 2026-05-09 14:00
16 bugs tagged patch in the BTS normal
The BTS contains patches fixing 16 bugs (17 if counting merged bugs), consider including or untagging them.
Created: 2026-04-06 Last update: 2026-05-09 14:00
Depends on packages which need a new maintainer normal
The packages that exim4 depends on which need a new maintainer are:
  • docbook-xml (#802368)
    • Build-Depends: docbook-xml
  • docbook-xsl (#802370)
    • Build-Depends: docbook-xsl
Created: 2023-09-01 Last update: 2026-05-09 11:30
1 new commit since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 5709df08e28eee78de5f28e7d9c36e3f6aee9b9c
Author: Andreas Metzler <ametzler@bebt.de>
Date:   Thu Apr 30 19:50:03 2026 +0200

    Replace upstream key list with updated upstream list.
    
    From https://downloads.exim.org/Exim-Maintainers-Keyring.asc
Created: 2026-04-30 Last update: 2026-05-03 14:03
lintian reports 4 warnings normal
Lintian reports 4 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-04-30 Last update: 2026-04-30 18:32
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-40686: (needs triaging) In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
  • CVE-2026-40687: (needs triaging) In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-04-30 Last update: 2026-05-06 13:30
debian/patches: 21 patches to forward upstream low

Among the 31 debian patches available in version 4.99.2-1 of the package, we noticed the following issues:

  • 21 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2024-10-19 Last update: 2026-04-30 07:05
testing migrations
  • This package will soon be part of the auto-perl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-05-07] Accepted exim4 4.99.2-1~bpo13+1 (source amd64 all) into stable-backports (Debian FTP Masters) (signed by: Andreas Metzler)
  • [2026-05-07] exim4 4.99.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-03] Accepted exim4 4.96-15+deb12u8 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Andreas Metzler)
  • [2026-05-03] Accepted exim4 4.98.2-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Andreas Metzler)
  • [2026-04-30] Accepted exim4 4.99.2-1 (source) into unstable (Andreas Metzler)
  • [2026-04-27] Accepted exim4 4.99.1-6 (source) into unstable (Andreas Metzler)
  • [2026-04-26] Accepted exim4 4.99.1-5 (source) into unstable (Andreas Metzler)
  • [2026-04-25] Accepted exim4 4.99.1-4 (source) into experimental (Andreas Metzler)
  • [2025-12-28] Accepted exim4 4.99.1-3 (source) into experimental (Andreas Metzler)
  • [2025-12-27] Accepted exim4 4.99.1-2 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Andreas Metzler)
  • [2025-12-23] Accepted exim4 4.99.1-1~bpo13+1 (source) into stable-backports (Andreas Metzler)
  • [2025-12-23] exim4 4.99.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-21] Accepted exim4 4.99.1-1 (source) into unstable (Andreas Metzler)
  • [2025-12-21] exim4 4.99-7 MIGRATED to testing (Debian testing watch)
  • [2025-12-17] Accepted exim4 4.99-7~bpo13+1 (source) into stable-backports (Andreas Metzler)
  • [2025-12-17] Accepted exim4 4.99-7 (source) into unstable (Andreas Metzler)
  • [2025-12-13] Accepted exim4 4.99-6~bpo13+1 (source) into stable-backports (Andreas Metzler)
  • [2025-12-13] exim4 4.99-6 MIGRATED to testing (Debian testing watch)
  • [2025-11-30] Accepted exim4 4.99-6 (source) into unstable (Andreas Metzler)
  • [2025-11-27] Accepted exim4 4.99-5 (source) into unstable (Andreas Metzler)
  • [2025-11-17] Accepted exim4 4.99-4~bpo13+1 (source amd64 all) into stable-backports (Debian FTP Masters) (signed by: Andreas Metzler)
  • [2025-11-16] exim4 4.99-4 MIGRATED to testing (Debian testing watch)
  • [2025-11-13] Accepted exim4 4.99-4 (source) into unstable (Andreas Metzler)
  • [2025-11-09] Accepted exim4 4.99-3 (source) into experimental (Andreas Metzler)
  • [2025-11-06] Accepted exim4 4.99-2 (source) into experimental (Andreas Metzler)
  • [2025-11-01] Accepted exim4 4.99-1 (source) into experimental (Andreas Metzler)
  • [2025-10-17] Accepted exim4 4.99~RC3-2 (source) into experimental (Andreas Metzler)
  • [2025-10-12] Accepted exim4 4.99~RC3-1 (source) into experimental (Andreas Metzler)
  • [2025-09-21] Accepted exim4 4.99~RC2-1 (source) into experimental (Andreas Metzler)
  • [2025-09-03] Accepted exim4 4.99~RC1-1 (source) into experimental (Andreas Metzler)
  • 1
  • 2
bugs [bug history graph]
  • all: 176 178
  • RC: 0
  • I&N: 85 87
  • M&W: 91
  • F&P: 0
  • patch: 16 17
  • help: 1
links
  • homepage
  • lintian (0, 4)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (92, -)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.99.1-1ubuntu1
  • 19 bugs
  • patches for 4.99.1-1ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing