-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 02 May 2026 06:52:57 +0200 Source: exim4 Binary: exim4 exim4-base exim4-base-dbgsym exim4-config exim4-daemon-heavy exim4-daemon-heavy-dbgsym exim4-daemon-light exim4-daemon-light-dbgsym exim4-daemon-mod exim4-daemon-mod-dbgsym exim4-dev exim4-mod-cyrus-sasl exim4-mod-cyrus-sasl-dbgsym exim4-mod-ldap exim4-mod-ldap-dbgsym exim4-mod-mysql exim4-mod-mysql-dbgsym exim4-mod-pam exim4-mod-pam-dbgsym exim4-mod-perl exim4-mod-perl-dbgsym exim4-mod-postgresql exim4-mod-postgresql-dbgsym exim4-mod-spf exim4-mod-spf-dbgsym eximon4 eximon4-dbgsym Architecture: source amd64 all Version: 4.99.2-1~bpo13+1 Distribution: trixie-backports Urgency: high Maintainer: Exim4 Maintainers <pkg-exim4-maintainers@lists.alioth.debian.org> Changed-By: Andreas Metzler <ametzler@debian.org> Description: exim4 - metapackage to ease Exim MTA (v4) installation exim4-base - support files for all Exim MTA (v4) packages exim4-config - configuration for the Exim MTA (v4) exim4-daemon-heavy - Exim MTA (v4) daemon with extended features, including exiscan-ac exim4-daemon-light - lightweight Exim MTA (v4) daemon exim4-daemon-mod - Exim MTA (v4) daemon with minimal hard dependencies exim4-dev - header files for the Exim MTA (v4) packages exim4-mod-cyrus-sasl - exim4 Cyrus SASL authenticator module exim4-mod-ldap - exim4 LDAP lookup module exim4-mod-mysql - exim4 MySQL lookup module exim4-mod-pam - exim4 pam supprt module exim4-mod-perl - exim4 embedded perl module exim4-mod-postgresql - exim4 PostgreSQL lookup module exim4-mod-spf - exim4 SPF ACL module eximon4 - monitor application for the Exim MTA (v4) (X11 interface) Closes: 1127778 1135033 Changes: exim4 (4.99.2-1~bpo13+1) trixie-backports; urgency=medium . * Rebuild for trixie-backports. . exim4 (4.99.2-1) unstable; urgency=high . * Update Jeremy's key to get new signing subkey. Adds 745A3503EC71104253C5D4490F04D14A28EAFA16 * New upstream security release. +CVE-2026-40684 Possible crash with malicious DNS data when using musl libc On systems using musl libc (not glibc) due to an oddity in octal printing it is possible to crash the connection instance when malformed DNS data is present in PTR records. +CVE-2026-40685 Possible OOB read/write on corrupt JSON in header configurations using json operators on invalid externally-provided input could trigger heap corruption. +CVE-2026-40686 Possible OOB read with large UTF8 trailing characters configurations using utf8 operators on malformed utf8 in headers could trigger OOB reads and might trigger some data leak if error messages are required for subsequent emails in the current connection and similar malformed headers are present. +CVE-2026-40687 Possible OOB read/write with SPA authenticator in configurations using the SPA authentication driver to a hostile/compromised external SPA/NTLM connection it is possible to trigger an OOB read/write and crash the connection instance or possibly leak heap data to the instance. . exim4 (4.99.1-6) unstable; urgency=medium . * Add Conflicts: rmail to all exim4-daemon-flavours. (Closes: #1135033) * Drop -lnsl from GNU/Hurd default LIBS. It should only be necessary for NIS on GNU/Hurd, too. * Run wrap-and-sort -ast. . exim4 (4.99.1-5) unstable; urgency=low . * Add NEWS entry for NIS lookup removal. * Bump Standards-Version, no changes * 88_05-Resync-Changelog-entry-numbering.diff does not need forwarding, update metadata. * Add lintian override for empty dir in exim4-daemon-mod package. * [lintian] Rename debian/patches/*.dpatch * 85_dkim_defaults.diff: Update patch metadata * Fix links to upstream bug reports in changelog et al. (bugs.exim.org -> code.exim.org) * Upload to unstable. . exim4 (4.99.1-4) experimental; urgency=medium . [ Andreas Metzler ] * Stop building with NIS support. Scheduled for removal upstream in 4.101. https://code.exim.org/exim/exim/issues/3206 * Prefix quote_pgsql result with e to enable PostgreSQL C-style escapes. (Thanks, Jasen) (Closes: #1127778) * Cherry-pick fixes from upstream GIT master: + Fix memory leak in DNS lookups. + Bug 3192: Fix header collapse in auto-generated bounce message. + Bug 3204: force a 4xx SMTP response to end-of-data if the final close of the written spoolfile returns an error. + Bug 3215: Fix GnuTLS hostname verify of a server certificate with a zero-length Subject. * Drop debian/config-custom/*. It has been broken since 2005 782e4f21032d757f501decd5a095caca4fa291ca * Add dep on systemd|systemd-standalone-tmpfiles|systemd-tmpfiles to exim4-base. The generated directories are required for exim and dh_installtmpfiles does not add a dependency. . [ Luca Boccassi ] * Install and use sysusers.d/tmpfiles.d config files. Install sysusers.d and tmpfiles.d and use them. Stop manually calling adduser. This also allows image-based systems to be created with /usr/ only, and also allows for factory resetting a system and recreating /etc/ on boot. https://www.freedesktop.org/software/systemd/man/latest/sysusers.d.html . exim4 (4.99.1-3) experimental; urgency=medium . * Fix FTBFS on archs != x86_64. . exim4 (4.99.1-2) experimental; urgency=medium . * Add experimental exim4-daemon-mod variant, features with external deps are in separate packages that only ship a single dlopened module. * Cherry-pick from upstream Git master: + Fix linker argument order for dynamic modules. * Drop longtime superseded Suggests on spf-tools-perl. * Ship empty module dir in exim4-daemon-mod to avoid warning. Checksums-Sha1: 5a76027e88fc06c4a2e7d1595533808c552601fb 3416 exim4_4.99.2-1~bpo13+1.dsc 6e4022c5cdab96219f03b621465f777db636c8d5 494900 exim4_4.99.2-1~bpo13+1.debian.tar.xz 8dc2eb89a2f80495d8dcbec890f965cea7612318 144196 exim4-base-dbgsym_4.99.2-1~bpo13+1_amd64.deb 52e9e0867aa189ed0d06bc36b407074a8dd6c0ea 1107412 exim4-base_4.99.2-1~bpo13+1_amd64.deb 7a0affd9852aed335d95cf16de0c48e3442b2f9a 251848 exim4-config_4.99.2-1~bpo13+1_all.deb d328ee886c39d4fb4b69693d30330c40dd98a94d 1736572 exim4-daemon-heavy-dbgsym_4.99.2-1~bpo13+1_amd64.deb 2a71e429af45df51a4dacbb740b7a8606bd9aae4 707712 exim4-daemon-heavy_4.99.2-1~bpo13+1_amd64.deb ac1ed82439d151d5b726f62de3a997db1a2a9a1a 1532340 exim4-daemon-light-dbgsym_4.99.2-1~bpo13+1_amd64.deb cc37c1dfe1e90946acaa321d268774e4d489ad9a 649308 exim4-daemon-light_4.99.2-1~bpo13+1_amd64.deb c66d973c787abaf7398d87682e8dbbc8fde5ed93 1652320 exim4-daemon-mod-dbgsym_4.99.2-1~bpo13+1_amd64.deb f3239aed545164e2bf02da4ea58a60e7a438e881 715060 exim4-daemon-mod_4.99.2-1~bpo13+1_amd64.deb 6d4745068edbd71f952aacc4614a59433619d7c3 38724 exim4-dev_4.99.2-1~bpo13+1_amd64.deb b4a3329e7eb45a22fa5717f135cb040ac193d39e 14208 exim4-mod-cyrus-sasl-dbgsym_4.99.2-1~bpo13+1_amd64.deb 17a2751c272d1f53a5f0cb0c7283292181d0ba3d 6476 exim4-mod-cyrus-sasl_4.99.2-1~bpo13+1_amd64.deb 360c753a083ebf249cf4fc7f4f285960bf224c34 23284 exim4-mod-ldap-dbgsym_4.99.2-1~bpo13+1_amd64.deb 23dfc0a546aa80289bbb94fcbfbb05f1ec4433d5 10592 exim4-mod-ldap_4.99.2-1~bpo13+1_amd64.deb 6dda1d4f5186239ab1e13077def7adf0ae90fb63 22032 exim4-mod-mysql-dbgsym_4.99.2-1~bpo13+1_amd64.deb 89d0b77cddeb7fac5dd3457466afbec6e7ca9603 5496 exim4-mod-mysql_4.99.2-1~bpo13+1_amd64.deb a83b670eaccfaf6d5a6fa21b9f166ceff80d269b 6732 exim4-mod-pam-dbgsym_4.99.2-1~bpo13+1_amd64.deb de39b39878a9ee93bb551172cce66b65c15f8697 3396 exim4-mod-pam_4.99.2-1~bpo13+1_amd64.deb 914c3a972c1b90e92fbf69519826fb9ffca8e254 34552 exim4-mod-perl-dbgsym_4.99.2-1~bpo13+1_amd64.deb 8ff87daf2d80a7f7b5724e17ece33157e970dd47 5936 exim4-mod-perl_4.99.2-1~bpo13+1_amd64.deb f4eea1ca2880445f5737744051d01fbee9b8b935 13196 exim4-mod-postgresql-dbgsym_4.99.2-1~bpo13+1_amd64.deb 8283805b0ebc00686a4594be03f3224414da8f06 5388 exim4-mod-postgresql_4.99.2-1~bpo13+1_amd64.deb bccb1a1291780a2375c852c2bc5883bddb0edda4 20148 exim4-mod-spf-dbgsym_4.99.2-1~bpo13+1_amd64.deb e7a707d1f8c0723efc9586e74918e0c368d041bb 7636 exim4-mod-spf_4.99.2-1~bpo13+1_amd64.deb a83ee76cc8cee011566d30a3baa2277ae350573f 7208 exim4_4.99.2-1~bpo13+1_all.deb 6eed39d1bbc20ae1ff8d2772ed85537ba4299b4a 16956 exim4_4.99.2-1~bpo13+1_amd64.buildinfo 74a3f476e5255b818c9919c096be0ce7bd2d0a68 140048 eximon4-dbgsym_4.99.2-1~bpo13+1_amd64.deb ca0b24d2e9e4781339ca733cda164063bf7930b4 74328 eximon4_4.99.2-1~bpo13+1_amd64.deb Checksums-Sha256: 90aa54fa40c1d5e727167f3c399f64b7b4b4c23f99f2953c85f4fd043af7d001 3416 exim4_4.99.2-1~bpo13+1.dsc 00b87bbeb9550345d7dd5b3ea92eaa7729920ff2e0f7990fae430c449669fc54 494900 exim4_4.99.2-1~bpo13+1.debian.tar.xz 820cd1b32ae76c9a2935b2399c7fc6e5b3e4f5e6bc5899e816309ed8348cf0a4 144196 exim4-base-dbgsym_4.99.2-1~bpo13+1_amd64.deb 579f39dc8c07b336680c1b3be5627ae3b2c33baff90557ed19f0ae5bd0643109 1107412 exim4-base_4.99.2-1~bpo13+1_amd64.deb 95ac1062f96d822f1332639cd49cc1d9986b288b87d127faf61e91d9aa8270ef 251848 exim4-config_4.99.2-1~bpo13+1_all.deb 8ff7d8a485e9a1a7056645ab8665e67a8afd9e6f7ba86413d19d22c5fa709382 1736572 exim4-daemon-heavy-dbgsym_4.99.2-1~bpo13+1_amd64.deb 2f0916b5f86706df6b11884a2a69dadb17be40fe8229bd24ac43d8f6b49eb0ab 707712 exim4-daemon-heavy_4.99.2-1~bpo13+1_amd64.deb 80d840bd32d8e007a686b5853e4ee8783ebdbef58aa31345b5be42b5827bb897 1532340 exim4-daemon-light-dbgsym_4.99.2-1~bpo13+1_amd64.deb 8baacb9db767d669c5ef7638ca058b7b414da08429d9146ed7d1394573018e36 649308 exim4-daemon-light_4.99.2-1~bpo13+1_amd64.deb bdcbbea388d0424231ccaf8a6a15f2875f30f30c95d83add615c910fe39e66ae 1652320 exim4-daemon-mod-dbgsym_4.99.2-1~bpo13+1_amd64.deb b159b39f52e637eee32d639611133a31d6d9e7e758e8796152512e003ea2c847 715060 exim4-daemon-mod_4.99.2-1~bpo13+1_amd64.deb 29dbab6332bbcd0f826c15e90bce6da420110b213284c23b65fc2e5578bffd59 38724 exim4-dev_4.99.2-1~bpo13+1_amd64.deb 667aba4fdf4568ae2615494c4a6262e778f0361a2bb00191d4d7bcb9b39bce28 14208 exim4-mod-cyrus-sasl-dbgsym_4.99.2-1~bpo13+1_amd64.deb 1e967ca1966ce3f88932f3995ba66826db34f8104306bdc04f31592d0e143b08 6476 exim4-mod-cyrus-sasl_4.99.2-1~bpo13+1_amd64.deb 65475f6f91199f9565f993f80bb9b5ff1baeb1b6daddc337000eed951e0ebdb5 23284 exim4-mod-ldap-dbgsym_4.99.2-1~bpo13+1_amd64.deb e27b5498a56b1087fe6ea826c16af2fd9803f052c408d54547c3b2ec78571155 10592 exim4-mod-ldap_4.99.2-1~bpo13+1_amd64.deb 747dc25e124eb1fccbb713327b0f66af7bd7ee27847db43d200992d78c6a6e16 22032 exim4-mod-mysql-dbgsym_4.99.2-1~bpo13+1_amd64.deb 351e19c8b0188780e05f85facfd0030dc66405f44e2bbce90529f6bc1d09bd1e 5496 exim4-mod-mysql_4.99.2-1~bpo13+1_amd64.deb 690fef1eda05c71807ed78170add4d6896f4fc18d4f7742140eeb5bc36e5b90e 6732 exim4-mod-pam-dbgsym_4.99.2-1~bpo13+1_amd64.deb fbc6db43e5ff51761a55e96b9ddb3ba458d6e85a81e61f6178007df0f88776bb 3396 exim4-mod-pam_4.99.2-1~bpo13+1_amd64.deb 3615476fc5cb2524ccd6779854d8bd49451973e70dd903f27dff0987509aaa43 34552 exim4-mod-perl-dbgsym_4.99.2-1~bpo13+1_amd64.deb bf71dc10feda6372737f90ccef904fb2c52080264d8257d4eaf971981a4818f4 5936 exim4-mod-perl_4.99.2-1~bpo13+1_amd64.deb 4b8176a5abeb4beb2780262ebe275e38ac49a8d2b678fc5e238e0875a6910c57 13196 exim4-mod-postgresql-dbgsym_4.99.2-1~bpo13+1_amd64.deb d8e6c0cde2464a4ace45ba8d9f8d3d42597c9b55e04ef5ca0aa61d6bfd5e0606 5388 exim4-mod-postgresql_4.99.2-1~bpo13+1_amd64.deb dc2e1015b5bb2e4d6116776d640779338bddd249dc7333658f3624bceb1f270c 20148 exim4-mod-spf-dbgsym_4.99.2-1~bpo13+1_amd64.deb 5341d67483838fce0ae6f009c971c3aa59fde0b450f06f75081e1fe0f80590fc 7636 exim4-mod-spf_4.99.2-1~bpo13+1_amd64.deb 62203cb42341af066fe88e80a7242bca46f49b577d611410ab03999cb64bcaeb 7208 exim4_4.99.2-1~bpo13+1_all.deb b82d2db8431d26429ced6c3f7f00e8c19b960c7aecfcad325aa5399bf70a3eb5 16956 exim4_4.99.2-1~bpo13+1_amd64.buildinfo 3f3f188bb0c87fd6d25f8ed1dfedeed7de54650b78f4f42f21f7a383492fc688 140048 eximon4-dbgsym_4.99.2-1~bpo13+1_amd64.deb 151f997d24dbd9dd03e98464f8a58c5156fb16be6ab8b4ed3498f4af5fa95cd1 74328 eximon4_4.99.2-1~bpo13+1_amd64.deb Files: d3768b564db4d482e7ab472b69e8421e 3416 mail standard exim4_4.99.2-1~bpo13+1.dsc 45b22aec7820e1c732710ea8e852aa6f 494900 mail standard exim4_4.99.2-1~bpo13+1.debian.tar.xz fd922263756112cc37c708f07c1dd480 144196 debug optional exim4-base-dbgsym_4.99.2-1~bpo13+1_amd64.deb 1d032cea9f802a6598c798e17969afa0 1107412 mail optional exim4-base_4.99.2-1~bpo13+1_amd64.deb 5ba99d85b1a779a6efd7de02071ab15e 251848 mail optional exim4-config_4.99.2-1~bpo13+1_all.deb d91a72d759fdc25d0a333d254492da7a 1736572 debug optional exim4-daemon-heavy-dbgsym_4.99.2-1~bpo13+1_amd64.deb c7ff58b95dc61bc1fe070181ef1cb3c9 707712 mail optional exim4-daemon-heavy_4.99.2-1~bpo13+1_amd64.deb 05fac029adc9e03ddd7641466c534468 1532340 debug optional exim4-daemon-light-dbgsym_4.99.2-1~bpo13+1_amd64.deb bc0c484eb0e1bc89530bb4ffe73714ee 649308 mail optional exim4-daemon-light_4.99.2-1~bpo13+1_amd64.deb 4091816a6937d1275ae4b0a6ec73966d 1652320 debug optional exim4-daemon-mod-dbgsym_4.99.2-1~bpo13+1_amd64.deb 1720c88de908c92638733b3524aaf20e 715060 mail optional exim4-daemon-mod_4.99.2-1~bpo13+1_amd64.deb 6c1d2ea880b39953b069510729600219 38724 mail optional exim4-dev_4.99.2-1~bpo13+1_amd64.deb 5d1aee00442fcdb7a7e013cb3c082fc6 14208 debug optional exim4-mod-cyrus-sasl-dbgsym_4.99.2-1~bpo13+1_amd64.deb 28f087e16b14114a4683c03d0e8ddaac 6476 mail optional exim4-mod-cyrus-sasl_4.99.2-1~bpo13+1_amd64.deb 3a848f854dd56144771401c053d56a29 23284 debug optional exim4-mod-ldap-dbgsym_4.99.2-1~bpo13+1_amd64.deb 8b57dcd37c75630815cdd16fbb612aa4 10592 mail optional exim4-mod-ldap_4.99.2-1~bpo13+1_amd64.deb b3594fcb29249946ba5ee44493d49a9b 22032 debug optional exim4-mod-mysql-dbgsym_4.99.2-1~bpo13+1_amd64.deb 6c3e47b4d5db60a92623a20d9d26c16e 5496 mail optional exim4-mod-mysql_4.99.2-1~bpo13+1_amd64.deb 45bbb7df0ddd7a128091d9aca24c4e92 6732 debug optional exim4-mod-pam-dbgsym_4.99.2-1~bpo13+1_amd64.deb 763ffb1d22931539d6c821ed7953291e 3396 mail optional exim4-mod-pam_4.99.2-1~bpo13+1_amd64.deb ad551f614aff7fa2c49a0a925c2dccee 34552 debug optional exim4-mod-perl-dbgsym_4.99.2-1~bpo13+1_amd64.deb 8466f48bc0013482f807c5ae91f7de73 5936 mail optional exim4-mod-perl_4.99.2-1~bpo13+1_amd64.deb 9c303486c6ad7e26e43afc8a33b77fdc 13196 debug optional exim4-mod-postgresql-dbgsym_4.99.2-1~bpo13+1_amd64.deb 002948720ebff4a35bac312cf159a51d 5388 mail optional exim4-mod-postgresql_4.99.2-1~bpo13+1_amd64.deb edb44f3013dfd3b863cea302c4fdaf17 20148 debug optional exim4-mod-spf-dbgsym_4.99.2-1~bpo13+1_amd64.deb e8b946ea6f1bbfdf7b93b11389081abb 7636 mail optional exim4-mod-spf_4.99.2-1~bpo13+1_amd64.deb 79a58aad09b0bce007d3bc73a98f4c73 7208 mail optional exim4_4.99.2-1~bpo13+1_all.deb 709ecf91ce7251900095de26da3242ba 16956 mail standard exim4_4.99.2-1~bpo13+1_amd64.buildinfo 6f40bef1c667d8a72fa61f78b91340eb 140048 debug optional eximon4-dbgsym_4.99.2-1~bpo13+1_amd64.deb 9b567a75bbcd656b581dd7f37b1f205f 74328 mail optional eximon4_4.99.2-1~bpo13+1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmn6wlQACgkQpU8BhUOC FIQTGw/+O7E9sa0eGOGeRy142pFPuV3n/4+iNLtmOcUwn8lPoqMAd4aZqiLfGlN/ zQ6yFLo5Ek8xCHDr6n2LGlzplxdFelOzQNtrgI0u2wy5sh1GQnl72Rl7f1HyePoz M4SusStGExawCHFlgeQzzH7trCeAMV1Ga7AYkLmqK4S+xoYl3ftydMIWSZN9s4PJ AwAj74OXqURy3TyURffJZpj2rtL7674yBKvsDiK0FfvGxMG3HbbLoWGjd5UAjsNC D71xPe+nfzTwTrr8lsCfOpmzoB2fa2gDPVft+bz494UNQznwD12yjxWJXkmHBNO4 bqq5OttH56pH8dY8nBJTYIF/Zrq1CdCQIKC0Vs0THn8wPUMNjyJJ5aeeHEzygfcH zl5kUw+lNvh/drrf/5B6IrgozStRpoJnBvbreHHm0feJBBF+l3Oy8A8fBL/g9UE8 rsdiV+2OUkQd6Wd59qw4zNJpaEjhjD9rOQTSi9VuAIHRpjwPzybXRNd98pdqJ3BQ 64OULTxTvGFhaf8WI9QtTRE2NUzDCjE9ATvdxVEjPTpi/MzHrwqUqDcZ3XxcKN75 J5rPplXuhkDLRvX7CN/xOoaNEocO3K6IX0TKsr+KGUwHCeUz4giI25/CQe7SmvVC 2xUyNmEA4gGep7QLOqse0vXUu+BFhDHpZlShxyL8hDqChO9qJFs= =ekNE -----END PGP SIGNATURE-----