-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 27 May 2026 18:58:40 +0200 Source: exim4 Binary: exim4-base exim4-base-dbgsym exim4-daemon-heavy exim4-daemon-heavy-dbgsym exim4-daemon-light exim4-daemon-light-dbgsym exim4-dev eximon4 eximon4-dbgsym Architecture: amd64 Version: 4.98.2-1+deb13u3 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Andreas Metzler Description: exim4-base - support files for all Exim MTA (v4) packages exim4-daemon-heavy - Exim MTA (v4) daemon with extended features, including exiscan-ac exim4-daemon-light - lightweight Exim MTA (v4) daemon exim4-dev - header files for the Exim MTA (v4) packages eximon4 - monitor application for the Exim MTA (v4) (X11 interface) Changes: exim4 (4.98.2-1+deb13u3) trixie-security; urgency=high . * Cherry-pick fix for EXIM-Security-2026-05-19.1 from 4.99.4. Security: PROXYv2 parser: reject PROXY frames whose declared payload length is too short for the claimed address family (12 bytes for TCPv4/0x11, 36 bytes for TCPv6/0x21). Previously a frame with family=0x21 and len=0 caused 16 bytes of uninitialized stack to be formatted as the sender's IPv6 address and disclosed in the SMTP greeting banner. Affects configurations with SUPPORT_PROXY and `hosts_proxy` set. Reported by Warisjeet Singh (sin99xx). Checksums-Sha1: 2c7a55f6763f99b7baf67900fdc5bbd414828fbf 139508 exim4-base-dbgsym_4.98.2-1+deb13u3_amd64.deb b99beb65de3a0d659b1c7942833861b056d4eed0 1142672 exim4-base_4.98.2-1+deb13u3_amd64.deb 95d48cde775730757bf42b73ce71020539a0c2f6 1689920 exim4-daemon-heavy-dbgsym_4.98.2-1+deb13u3_amd64.deb fdb5ea0c45f12930f2eb50bba33c78e0a383d10c 691272 exim4-daemon-heavy_4.98.2-1+deb13u3_amd64.deb ee25c097411553d5de2323fe0b830a3101ccffc2 1487844 exim4-daemon-light-dbgsym_4.98.2-1+deb13u3_amd64.deb b1a425ec28fbbfc282b64273130b7562a9bfb924 631200 exim4-daemon-light_4.98.2-1+deb13u3_amd64.deb 12eedecd473d6a20afd0c36832e16d170fe4d10c 36400 exim4-dev_4.98.2-1+deb13u3_amd64.deb 32640917e69f79177999284e3a648c34b07756be 11324 exim4_4.98.2-1+deb13u3_amd64-buildd.buildinfo 8de8b14751bbaea76a899a89e226c6210214746c 138600 eximon4-dbgsym_4.98.2-1+deb13u3_amd64.deb 370199da304f5b42d0c9181077974ce4ccf2cfb7 72024 eximon4_4.98.2-1+deb13u3_amd64.deb Checksums-Sha256: d45756c2250dd44e1101738fe538771f9c9ce4fb48e09c378b9e122fca2f5b51 139508 exim4-base-dbgsym_4.98.2-1+deb13u3_amd64.deb c4f09994e5e0b2d42a8928d2d2ed66f4603d2bad6e1b61e15c98f116f22b11b5 1142672 exim4-base_4.98.2-1+deb13u3_amd64.deb 55e38153ceda3dcb9e029c22e13d16199c617934e5cf95f986f46c73dee289b3 1689920 exim4-daemon-heavy-dbgsym_4.98.2-1+deb13u3_amd64.deb 89dd6cfc5cd25d904bb049d45d5fd9eb03c344ff87a09e022588206fde4e6de2 691272 exim4-daemon-heavy_4.98.2-1+deb13u3_amd64.deb 9ffc48061c956baa74ac62ba2688f6e0e381d27df078580cf4c9cd5103bb7dfe 1487844 exim4-daemon-light-dbgsym_4.98.2-1+deb13u3_amd64.deb 9e89c05bf4c668ad8d56f8bbe11b795bf5ebd03b8b8bc22a57aa5253020cd065 631200 exim4-daemon-light_4.98.2-1+deb13u3_amd64.deb 5d6fabd8b1c88a524f8d17e46de2b58b161870a2e5485046fa292f6b240598cf 36400 exim4-dev_4.98.2-1+deb13u3_amd64.deb 8e84ddbdfc6758fbf97c74499fa7f6b2ae71b0713d7c8f056ad7692b1f549484 11324 exim4_4.98.2-1+deb13u3_amd64-buildd.buildinfo 6a6eba279675f2fb6b4e59b386cc140553f93e525ceee4f1ccb03e164f49c87d 138600 eximon4-dbgsym_4.98.2-1+deb13u3_amd64.deb ca422e935b3d156c8a0c39ce02dde028785e97d8f77e374f29f71cfd1f998f71 72024 eximon4_4.98.2-1+deb13u3_amd64.deb Files: 2f8215fd1f3e6e06ff81725aa1267abe 139508 debug optional exim4-base-dbgsym_4.98.2-1+deb13u3_amd64.deb cafc4438de4249efbfdfd419cb5aa3c2 1142672 mail optional exim4-base_4.98.2-1+deb13u3_amd64.deb bf1b17a6d6303da9360b51083c8824bb 1689920 debug optional exim4-daemon-heavy-dbgsym_4.98.2-1+deb13u3_amd64.deb 7c7b4d7d93d5f4aa7de1a6de8b258210 691272 mail optional exim4-daemon-heavy_4.98.2-1+deb13u3_amd64.deb 11522e363446073cf0e5a4cf734c0915 1487844 debug optional exim4-daemon-light-dbgsym_4.98.2-1+deb13u3_amd64.deb 119c908a14ba6cb2a9733a0d606850f2 631200 mail optional exim4-daemon-light_4.98.2-1+deb13u3_amd64.deb e85a5f89a91b9057a0300fd47b47e379 36400 mail optional exim4-dev_4.98.2-1+deb13u3_amd64.deb 377f7594c1522bb56d547e4a2564bb40 11324 mail standard exim4_4.98.2-1+deb13u3_amd64-buildd.buildinfo 192ce72b6229b9b9a3f48775bc5f6323 138600 debug optional eximon4-dbgsym_4.98.2-1+deb13u3_amd64.deb 6b71216d630df069f9e34106756eeabf 72024 mail optional eximon4_4.98.2-1+deb13u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEb5EwsJvHBEjqIJYIbheoBegwXLIFAmoYeAkACgkQbheoBegw XLL17g//TgWTtFX6VzS73BVfTLI+f8hXFFkOV6Go43ihqBmMtShFgLWT2LQcMOPv jR5QhnAejJYDqUhsjiUWh/fAmX8W7KuS31Or+bbFJObpHvL6fpW62hnP2N0jPd4j 1bbd9YD8QBFV6r0mXlPvlnsNh0vrc/o+yLBA9JWFrpkIXiH51uTyzItjg4B00cV7 IyjutoKzIXO5LJBCXhYyzA2XRmiBU3tfDYpe01sauLbi5TYt8H6a11v1127sLCL0 WO1L8ZKZv/LMOeyCKQO6QvK+ACg/y3YYD9V8pEUMpLWgDuNBaGavS3BbhwwguD2k HbMb55o8SJM5F7kTgHewRKxQBxiN0DoshL5B5Oho8mmhvQ9X6fx1IJvpY1UvdNXk Gmz7B9WN450KrWmfRPIL9+Q49wE0jJg1wKWtLIB4l3MT+3Uep9vdlDF5j/WNf34W vjuALWrFmfSVCBaMGyctXTw/zY05ENpD7UfxSJKHRVWPUhepBCOFg9NPbQnqblO1 hfHvl6jE4oKiEEzhjFFqoR0t1Pgdhi6mjWFNvLWCZE1Gm3xqghZsWp3u4eDtav0e nxOzUNXzh8tPdjnSHs0NsXPLbx5bhWJphopnb/5+EZCNUMrp+qOTHpJcVpW45S5I pcARgtr0vBQTtKM9zIYtMUeA/SD75TlVNAvDGhRDbid0zA11yFY= =0kyA -----END PGP SIGNATURE-----