-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Oct 2023 18:04:33 +0200 Source: exim4 Architecture: source Version: 4.97~RC1-2 Distribution: unstable Urgency: high Maintainer: Exim4 Maintainers <pkg-exim4-maintainers@lists.alioth.debian.org> Changed-By: Andreas Metzler <ametzler@debian.org> Changes: exim4 (4.97~RC1-2) unstable; urgency=high . * Address SPA authenticator vulnerabilities (CVE-2023-42114, CVE-2023-42115, CVE-2023-42116) - Auths: fix possible OOB write in external authenticator (CVE-2023-42115) - Auths: use uschar more in spa authenticator - Auths: fix possible OOB write in SPA authenticator (CVE-2023-42116) - Auths: fix possible OOB read in SPA authenticator (CVE-2023-42114) Checksums-Sha1: 0ffd208db562cad5481507b11ad9f06d6c638108 2951 exim4_4.97~RC1-2.dsc 12008469a81d5e4789fbab6db5bdb689beb23c3c 472052 exim4_4.97~RC1-2.debian.tar.xz Checksums-Sha256: 9268697baff1794a9d85bbe86c17a734e2192e129182c373fe82ec9d6aaef03d 2951 exim4_4.97~RC1-2.dsc 70b1aab53fa6dd0e4a8c246ae82ba7aff1d923d14c10f922385591c2447c977b 472052 exim4_4.97~RC1-2.debian.tar.xz Files: dc9c5964980fc403ed023fd5442e8ddd 2951 mail standard exim4_4.97~RC1-2.dsc ad023b60592205d295cdef484bdbf465 472052 mail standard exim4_4.97~RC1-2.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmUZmUUACgkQpU8BhUOC FITS5RAAol2QQJGaTbMp0oikciwDHYOAH5bmIiSoHN9y+jY8pOa/zvcflGWgrGa4 OogCtw5bLUG+vmmp/lfeZg2WmCMLl2tUvfd3Mhj2AOM8WjaKnSqEPaGC3eq3PmWg 46w8jQqxWlENZnJddhEMQVYlLIkLTOTRZoND8E7G7GSa1NMxEoSQcujSS9iDMOpx H5a9n1lPdx8JSv82+FlNxEQGWGky+i+5JVxs+OVpPbcxfzJiytCgPJVadDw/QBcx U66nwVSsP2cy0Ivg/OrJsyaVibgWNRwc7YR2qcOvcdSwCmkex5Rz4y+KRrDUlRV9 QS82lmZS6OtbHkh7OpxHW+tHeooCWJQuaiWODKmEfaRTt36TL4UDLN5kwe2zg8YV +/TsVMbGPGgdRSNY1LlBbJ1tiWRKAHPcG33uZs+0cvS36+vNpypj1LdqOmagKAth Qwm9hpMxnhPgb6qmKjQgkJp+W2Y/k1Ko8+/hrdOoxyLzlfXSQk0PlZ6KyZWDtjc+ Oil9R/UAlzXBxsdHrMoE8Pne5nZnT0n6WhimqExgUKADZ2ZLTuoXPQejuaxbySJE SSbt4G0rjCwbY1m2vIe70oglXJLifJiS8EWI3KKl+vURLRlCOrugm2E8X72B+cPg hz/6v9fV5DGxUpxjgfalhoN0z7VIDiGD3glv+mHd1TVboJzCEVY= =vzNg -----END PGP SIGNATURE-----