Package: release.debian.org Severity: serious User: release.debian.org@packages.debian.org Usertags: unblock X-Debbugs-Cc: exim4@packages.debian.org Please unblock package exim4 I think this might be unnecessary, but better safe than sorry. exim 4.92.2 is an upstream security release based on 4.94+fixes branch. The issues are severe (Local Privilege Escalations and Remote Code Executions), see https://www.qualys.com/2021/05/04/21nails/21nails.txt or http://exim.org/static/doc/security/CVE-2020-qualys/ for the gory details. https://lists.debian.org/debian-security-announce/2021/msg00093.html As we are already shipping head of 4.94+fixes as of before the embargoed changes adding adding 59 patches instead moving to the new release would not have made the changeset smaller but would have increased the chance of errors. It makes the debdiff a little bit unwieldy, we are dropping a load of patches (debian/patches/74_ which are already part of the tarball. For your convenience I am providing the patch-series for the actual upstream changes in addition to the debdiff. unblock exim4/4.94.2-1 thanks in advance, cu Andreas -- `What a good friend you are to him, Dr. Maturin. His other friends are so grateful to you.' `I sew his ears on from time to time, sure'
Attachment:
patch-series.tar.xz
Description: application/xz
Attachment:
from-19_to_4.94.2-1.diff.xz
Description: application/xz