Mailing List Archive

Exim 4.87.1 released
I've uploaded Exim 4.87.1 to:

ftp://ftp.exim.org/pub/exim/exim4/old/
git://git.exim.org/exim.git (tag exim-4_87_1)

Whilst this release is superseeded by 4.88 already, you're urged
to upgrade to 4.87.1, if 4.88 isn't an option for you yet.

No features are added or removed. This release contains
just a fix for CVE-2016-9963

- Fix CVE-2016-9963 - Info leak from DKIM. When signing DKIM, if
either LMTP or PRDR was used for delivery, the key could appear in
logs. Additionally, if the experimental feature "DSN_INFO" was used,
it could appear in DSN messages (and be sent offsite).

For details about the CVE please see

https://exim.org/static/doc/CVE-2016-9963.txt

The release files for 4.87.1 are signed with the PGP key 0xF69376CE,
which has a uid "Heiko Schlittermann (HS12-RIPE) <hs@schlittermann.de>".
Please use your own discretion in assessing what trust paths you might
have to this uid.

In case on any problems please contact us on exim-users@exim.org
or on the IRC channel #exim at freenode.

Best regards from Dresden/Germany
Viele Grüße aus Dresden
Heiko Schlittermann
--
SCHLITTERMANN.de ---------------------------- internet & unix support -
Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
gnupg encrypted messages are welcome --------------- key ID: F69376CE -
! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -
Re: Exim 4.87.1 released [ In reply to ]
Heiko Schlittermann <hs@schlittermann.de> (So 25 Dez 2016 11:41:15 CET):
> I've uploaded Exim 4.87.1 to:
>
> ftp://ftp.exim.org/pub/exim/exim4/old/
> git://git.exim.org/exim.git (tag exim-4_87_1)

For easy checking the integrity of the package files
I provide the sha256 sums:

ee80359a8ee910e553cdf2f9beac26a20e346478080a010d43ad3d906b332427 exim-4.87.1.tar.gz
04be72f48923c5bd9fb45c08a157f38dc5d58ed43b7ec5eba18f66055ffcad1c exim-pdf-4.87.1.tar.gz
e086aba511333d94d283cebdbea123f718f816fc8706e64da8441f5fda77f2fd exim-postscript-4.87.1.tar.gz
d4b7994c89240d2f9a9fcd7a2dffa4b72f14379001a24266f4dbb0fbe5131514 exim-4.87.1.tar.bz2
eba7019d95ba079b895c6e81df8c2c79573d2fc18797f0bcfd6dc29c0471b19b exim-pdf-4.87.1.tar.bz2
b61985893d10d4ad888f5fac5564ff4b0f23bd24dc986031dace32bfcd835a1b exim-postscript-4.87.1.tar.bz2

But you're better off checking the GPG signatures.

Best regards from Dresden/Germany
Viele Grüße aus Dresden
Heiko Schlittermann
--
SCHLITTERMANN.de ---------------------------- internet & unix support -
Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
gnupg encrypted messages are welcome --------------- key ID: F69376CE -
! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -