oss-sec mailing list archives

Re: Exim 4.95 invalid free


From: Evgeny Legerov <admin () vulndisco cc>
Date: Sat, 6 Aug 2022 19:40:49 +0300

My bad.

Fix is here https://github.com/Exim/exim/commit/51be321b27825c01829dffd90f11bfff256f7e42

On 06.08.2022 17:47, John Helmert III wrote:
Hi, please keep in mind the list content guidelines:

"At least the most essential part of your message (e.g., vulnerability detail and/or exploit) should be directly included in 
the message itself (and in plain text), rather than only included by reference to an external resource. Posting links to relevant 
external resources as well is acceptable, but posting only links is not. Your message should remain valuable even with all of the 
external resources gone."

Do you have any upstream references or commits of the fix?

On Sat, Aug 06, 2022 at 12:06:36PM +0300, Evgeny Legerov wrote:
Hi,


The issue has been silently fixed in Exim 4.96 -
https://github.com/ivd38/exim_invalid_free



regards,

-e



Current thread: