[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#988067: marked as done (unblock: exim4/4.94.2-1)



Your message dated Tue, 04 May 2021 18:06:36 +0100
with message-id <4511e3f6f3a8c4f44bdb60fa6808d4c3707b51d4.camel@adam-barratt.org.uk>
and subject line Re: Bug#988067: unblock: exim4/4.94.2-1
has caused the Debian Bug report #988067,
regarding unblock: exim4/4.94.2-1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
988067: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=988067
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: release.debian.org
Severity: serious
User: release.debian.org@packages.debian.org
Usertags: unblock
X-Debbugs-Cc: exim4@packages.debian.org

Please unblock package exim4

I think this might be unnecessary, but better safe than sorry.

exim 4.92.2 is an upstream security release based on 4.94+fixes branch.
The issues are severe (Local Privilege Escalations and Remote Code
Executions), see
https://www.qualys.com/2021/05/04/21nails/21nails.txt or
http://exim.org/static/doc/security/CVE-2020-qualys/ for the gory
details.
https://lists.debian.org/debian-security-announce/2021/msg00093.html

As we are already shipping head of 4.94+fixes as of before the embargoed
changes adding adding 59 patches instead moving to the new release would
not have made the changeset smaller but would have increased the chance
of errors. It makes the debdiff a little bit unwieldy, we are dropping a
load of patches (debian/patches/74_ which are already part of the
tarball. For your convenience I am providing the patch-series for the
actual upstream changes in addition to the debdiff.

unblock exim4/4.94.2-1

thanks in advance, cu Andreas
-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'

Attachment: patch-series.tar.xz
Description: application/xz

Attachment: from-19_to_4.94.2-1.diff.xz
Description: application/xz


--- End Message ---
--- Begin Message ---
On Tue, 2021-05-04 at 18:57 +0200, Andreas Metzler wrote:
> Please unblock package exim4
> 
> I think this might be unnecessary, but better safe than sorry.
> 
> exim 4.92.2 is an upstream security release based on 4.94+fixes
> branch.
> 

I already added a hint, but for completeness - unblocked (and urgented,
given the number of issues), thanks.

Regards,

Adam

--- End Message ---

Reply to: