Hi,
anyone at Sophos can comment on the EXIM vulns, for instance as described here? https://www.heise.de/news/Jetzt-patchen-Kritische-Root-Luecken-bedrohen-Exim-Mail-Server-6036724.html
Thanks
Joerg
This thread was automatically locked due to age.
Hi,
anyone at Sophos can comment on the EXIM vulns, for instance as described here? https://www.heise.de/news/Jetzt-patchen-Kritische-Root-Luecken-bedrohen-Exim-Mail-Server-6036724.html
Thanks
Joerg
Hi Harsh,
I can't see any Exim fixes in the release notes. What am I missing?
Thanks,
Marcel
The Vulnerabilities was disclosed yesterday evening. UTM 9.706 was released two days ago. Therefore it cannot include any kind of fixes.
__________________________________________________________________________________________________________________
so why have the release notes been posted here?
UTM9.706 was built some time ago and is not related to Exim, as it was already finished before Exim vulnerabilities were disclosed.
__________________________________________________________________________________________________________________
I understand. When can we expect news about the newest Exim vulnerabilities?
Hi Marcel Bruckner,
We'll update the following blog post with the new information as it becomes available:
Thanks,
JFYI: The Advisory was updated with the latest information.
__________________________________________________________________________________________________________________
The mentioned protection IPS rules are only available on XG 550 or higher models. I would appreciate also release it for models at least +210 or higher.
Thanks
Can't we have just patched exim-related files and instructions in the meantime? I understand utm has no hotfix option out of the box. But such a critical flaw can't wait for a week.
We just recovered from the hafnium nightmare and this is the next critical issue where we can just sit and wait to be exploited.
Can't we have just patched exim-related files and instructions in the meantime? I understand utm has no hotfix option out of the box. But such a critical flaw can't wait for a week.
We just recovered from the hafnium nightmare and this is the next critical issue where we can just sit and wait to be exploited.