GSA-6400-1: Exim4 Security Update
Gnoppix Security has issued a critical update for Exim4, the default mail transfer agent. Two vulnerabilities allow remote attackers to execute arbitrary code.
The flaws involve a use-after-free condition and a heap-based buffer overflow in the handling of specific message data. An attacker could exploit these to crash Exim or gain full control of a mail server.
Affected Versions
- Gnoppix 23/25 (Bookworm): Exim4 packages are vulnerable.
- Gnoppix 25 (Trixie): Also affected.
Immediate Action Required
System administrators must upgrade the exim4-daemon-heavy or exim4-daemon-light packages immediately. No workaround exists for unpatched systems.
Fix and Upgrade Process
The fix is included in Exim version 4.98.1. Update by running apt update then apt upgrade exim4-*. A full reboot is unnecessary, but the Exim service must be restarted after the upgrade. - Please update your systems.