Path to this page:
Subject: CVS commit: pkgsrc/mail/exim
From: David Brownlee
Date: 2025-03-26 19:27:27
Message id: 20250326182727.403D5FBE1@cvs.NetBSD.org
Log Message:
Updated mail/exim to 4.98.2 - exploitable UAF
Exim version 4.98.2
-------------------
This is a security release, addressing CVE-2025-30232
JH/01 Fix use-after-free notified by Trend Micro (ref: ZDI-CAN-26250).
Null out debug_pretrigger_buf pointer before freeing the buffer;
the use of this buffer by the storage management checks the pointer
for non-null before using it.
Files: