Please merge exim4 4.82.1-2 (main) from Debian unstable (main)

Bug #1348074 reported by Andreas Metzler
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
exim4 (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

Ubuntu's exim4 packages are based on Debian 4.82-8 and therefore missing these two fixes:

 exim4 (4.82.1-1) unstable; urgency=high
 .
   * New upstream security release, fixing CVE-2014-2957. This is a remote
     code execution flaw in Exim version 4.82 (only) when built with DMARC
     support. Debian's binary packages are not built with DMARC support and
     therefore not vulnerable. However we want to fix this for people building
     their own binaries based on Debian's packaging.

 exim4 (4.82.1-2) unstable; urgency=high
 .
   * [87_double_expansion.diff] from upstream. Stop unwanted double expansion
     of arguments to mathematical comparison operations.
CVE-2014-2972

Please sync with Debian unstable (or experimental).

thanks, cu Andreas

Related branches

CVE References

Revision history for this message
Robie Basak (racb) wrote :

Thank you for taking the time for Ubuntu. I'll triage this as a "exim4 needs a merge" bug, to resync against Debian's 4.82.1-1. I don't think we need a security bug as it'd be fixed by the merge and because of its priority the merge would probably come first. If anyone else wants a bug to specifically track the security issue, feel free to file it.

summary: - sync with Debian - minor security fix
+ Please merge exim4 4.82.1-2 (main) from Debian unstable (main)
tags: added: upgrade-software-version
Changed in exim4 (Ubuntu):
status: New → Triaged
importance: Undecided → Medium
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package exim4 - 4.82.1-2ubuntu1

---------------
exim4 (4.82.1-2ubuntu1) utopic; urgency=low

  * Merge from Debian unstable (LP: #1348074). Remaining changes:
    - Show Ubuntu distribution on smtp:
      + debian/patches/fix_smtp_banner.patch: updated SMTP banner
        with Ubuntu distribution
      + debian/control: added lsb-release build dependency
    - Don't provide default-mta; in Ubuntu, we want postfix to be the
      default.

exim4 (4.82.1-2) unstable; urgency=high

  * [87_double_expansion.diff] from upstream. Stop unwanted double expansion
    of arguments to mathematical comparison operations.

exim4 (4.82.1-1) unstable; urgency=high

  * New upstream security release, fixing CVE-2014-2957. This is a remote
    code execution flaw in Exim version 4.82 (only) when built with DMARC
    support. Debian's binary packages are not built with DMARC support and
    therefore not vulnerable. However we want to fix this for people building
    their own binaries based on Debian's packaging.
 -- Robie Basak <email address hidden> Fri, 25 Jul 2014 15:53:09 +0000

Changed in exim4 (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.