{"id":"openSUSE-SU-2024:0007-1","summary":"Security update for exim","details":"This update for exim fixes the following issues:\n\nexim was updated to 4.97.1 (boo#1218387, CVE-2023-51766):\n\n  * Fixes for the smtp protocol smuggling (CVE-2023-51766)\n\nexim was updated to exim 4.96:\n\n  * Move from using the pcre library to pcre2.\n  * Constification work in the filters module required a major version\n    bump for the local-scan API.  Specifically, the 'headers_charset'\n    global which is visible via the API is now const and may therefore\n    not be modified by local-scan code.\n  * Bug 2819: speed up command-line messages being read in.  Previously a\n    time check was being done for every character; replace that with one\n    per buffer.\n  * Bug 2815: Fix ALPN sent by server under OpenSSL.  Previously the string\n    sent was prefixed with a length byte.\n  * Change the SMTP feature name for pipelining connect to be compliant with\n    RFC 5321.  Previously Dovecot (at least) would log errors during\n    submission.\n  * Fix macro-definition during '-be' expansion testing.  The move to\n    write-protected store for macros had not accounted for these runtime\n    additions; fix by removing this protection for '-be' mode.\n  * Convert all uses of select() to poll().\n  * Fix use of $sender_host_name in daemon process.  When used in certain\n    main-section options or in a connect ACL, the value from the first ever\n    connection was never replaced for subsequent connections.\n  * Bug 2838: Fix for i32lp64 hard-align platforms\n  * Bug 2845: Fix handling of tls_require_ciphers for OpenSSL when a value\n    with underbars is given.\n  * Bug 1895: TLS: Deprecate RFC 5114 Diffie-Hellman parameters.\n  * Debugging initiated by an ACL control now continues through into routing\n    and transport processes.\n  * The 'expand' debug selector now gives more detail, specifically on the\n    result of expansion operators and items.\n  * Bug 2751: Fix include_directory in redirect routers.  Previously a\n    bad comparison between the option value and the name of the file to\n    be included was done, and a mismatch was wrongly identified.\n  * Support for Berkeley DB versions 1 and 2 is withdrawn.\n  * When built with NDBM for hints DB's check for nonexistence of a name\n    supplied as the db file-pair basename.\n  * Remove the 'allow_insecure_tainted_data' main config option and the\n    'taint' log_selector.\n  * Fix static address-list lookups to properly return the matched item.\n    Previously only the domain part was returned.\n  * The ${run} expansion item now expands its command string elements after\n    splitting.  Previously it was before; the new ordering makes handling\n    zero-length arguments simpler.\n  * Taint-check exec arguments for transport-initiated external processes.\n    Previously, tainted values could be used.  This affects 'pipe', 'lmtp' and\n    'queryprogram' transport, transport-filter, and ETRN commands.\n    The ${run} expansion is also affected: in 'preexpand' mode no part of\n    the command line may be tainted, in default mode the executable name\n    may not be tainted.\n  * Fix CHUNKING on a continued-transport.  Previously the usabilility of\n    the facility was not passed across execs, and only the first message\n    passed over a connection could use BDAT; any further ones using DATA.\n  * Support the PIPECONNECT facility in the smtp transport when the helo_data\n    uses $sending_ip_address and an interface is specified.\n  * OpenSSL: fix transport-required OCSP stapling verification under session\n    resumption.\n  * TLS resumption: the key for session lookup in the client now includes\n    more info that a server could potentially use in configuring a TLS\n    session, avoiding oferring mismatching sessions to such a server.\n  * Fix string_copyn() for limit greater than actual string length.\n  * Bug 2886: GnuTLS: Do not free the cached creds on transport connection\n    close; it may be needed for a subsequent connection.\n  * Fix CHUNKING for a second message on a connection when the first was\n    rejected.\n  * Fix ${srs_encode ...} to handle an empty sender address, now returning\n    an empty address.\n  * Bug 2855: Handle a v4mapped sender address given us by a frontending\n    proxy.\n\nupdate to exim 4.95\n\n  * includes taintwarn (taintwarn.patch)\n  * fast-ramp queue run\n  * native SRS\n  * TLS resumption\n  * LMDB lookups with single key\n  * smtp transport option 'message_linelength_limit'\n  * optionally ignore lookup caches\n  * quota checking for appendfile transport during message reception\n  * sqlite lookups allow a 'file=\u003cpath\u003e' option\n  * lsearch lookups allow a 'ret=full' option\n  * command line option for the notifier socket\n  * faster TLS startup\n  * new main config option 'proxy_protocol_timeout'\n  * expand 'smtp_accept_max_per_connection'\n  * log selector 'queue_size_exclusive'\n  * main config option 'smtp_backlog_monitor'\n  * main config option 'hosts_require_helo'\n  * main config option 'allow_insecure_tainted_data'","modified":"2026-03-11T07:33:32.062814Z","published":"2024-01-03T20:12:49Z","related":["CVE-2022-3559","CVE-2023-42114","CVE-2023-42115","CVE-2023-42116","CVE-2023-42117","CVE-2023-42119","CVE-2023-51766"],"upstream":["CVE-2022-3559","CVE-2023-42114","CVE-2023-42115","CVE-2023-42116","CVE-2023-42117","CVE-2023-42119","CVE-2023-51766"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HHLYW3QLWRHGQXVXSQUL2DBTCFFCJGNB/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218387"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3559"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42114"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42115"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42116"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42117"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-51766"}],"affected":[{"package":{"name":"exim","ecosystem":"SUSE:Package Hub 15 SP5","purl":"pkg:rpm/suse/exim&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.97.1-bp155.5.9.1"}]}],"ecosystem_specific":{"binaries":[{"exim":"4.97.1-bp155.5.9.1","eximon":"4.97.1-bp155.5.9.1","eximstats-html":"4.97.1-bp155.5.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0007-1.json"}},{"package":{"name":"exim","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/exim&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.97.1-bp155.5.9.1"}]}],"ecosystem_specific":{"binaries":[{"exim":"4.97.1-bp155.5.9.1","eximon":"4.97.1-bp155.5.9.1","eximstats-html":"4.97.1-bp155.5.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0007-1.json"}}],"schema_version":"1.7.5"}