Comment 2 for bug 1843041

Revision history for this message
Alex Murray (alexmurray) wrote :

This bug was fixed in the package exim4 - 4.90.1-1ubuntu1.4
----------------
exim4 (4.90.1-1ubuntu1.4) bionic-security; urgency=medium

  * SECURITY UPDATE: remote command execution
    - debian/patches/CVE-2019-15846.patch: ensure not to interpret '\\'
      before '\0' in src/string.c
    - CVE-2019-15846

 -- Alex Murray <email address hidden> Wed, 04 Sep 2019 21:14:01 +0930