Hi,
anyone at Sophos can comment on the EXIM vulns, for instance as described here? https://www.heise.de/news/Jetzt-patchen-Kritische-Root-Luecken-bedrohen-Exim-Mail-Server-6036724.html
Thanks
Joerg
This thread was automatically locked due to age.
Hi,
anyone at Sophos can comment on the EXIM vulns, for instance as described here? https://www.heise.de/news/Jetzt-patchen-Kritische-Root-Luecken-bedrohen-Exim-Mail-Server-6036724.html
Thanks
Joerg
so why have the release notes been posted here?
UTM9.706 was built some time ago and is not related to Exim, as it was already finished before Exim vulnerabilities were disclosed.
__________________________________________________________________________________________________________________
I understand. When can we expect news about the newest Exim vulnerabilities?
Hi Marcel Bruckner,
We'll update the following blog post with the new information as it becomes available:
Thanks,
JFYI: The Advisory was updated with the latest information.
__________________________________________________________________________________________________________________
The mentioned protection IPS rules are only available on XG 550 or higher models. I would appreciate also release it for models at least +210 or higher.
Thanks
Can't we have just patched exim-related files and instructions in the meantime? I understand utm has no hotfix option out of the box. But such a critical flaw can't wait for a week.
We just recovered from the hafnium nightmare and this is the next critical issue where we can just sit and wait to be exploited.
I also agree that this should be addressed faster. For SG there is no workaround in the meantime. We can‘t just replace all SPAM Filers with eg. Sophos Cloud. There neds to be a small fix just for exim, what is taking so long?
Or handle the Exploits with IPS. Just waiting is not an option.
Sophos seems to miss so many things the past years..
I also agree that this should be addressed faster. For SG there is no workaround in the meantime. We can‘t just replace all SPAM Filers with eg. Sophos Cloud. There neds to be a small fix just for exim, what is taking so long?
Or handle the Exploits with IPS. Just waiting is not an option.
Sophos seems to miss so many things the past years..