Exim Product Security Update Advisory (CVE-2024-39929)

Overview

 

Exim has released a security update that addresses a vulnerability in its supplied products. Users of affected products are advised to update to the latest version.

 

 

Affected Products

 

Exim 4.97.1 version 

 

 

Resolved Vulnerabilities

 

Vulnerability in Exim MTA due to a RFC 2231 header parsing bug, which could allow remote attackers to deliver malicious attachments to a user’s inbox (CVE-2024-39929)

 

 

Vulnerability Patches

 

 

The latest updates have provided patches for the most recent vulnerabilities. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

Exim 4.98 version

 

 

Referenced Sites

 

[1] CVE-2024-39929 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-39929

[2] Exim through 4.97.1 misparses a multiline RFC 2231 header…

https://github.com/advisories/GHSA-7m4v-cwm7-4f2m