-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 27 May 2026 18:58:40 +0200 Source: exim4 Binary: exim4-base exim4-base-dbgsym exim4-daemon-heavy exim4-daemon-heavy-dbgsym exim4-daemon-light exim4-daemon-light-dbgsym exim4-dev eximon4 eximon4-dbgsym Architecture: armhf Version: 4.98.2-1+deb13u3 Distribution: trixie-security Urgency: high Maintainer: armhf Build Daemon (arm-ubc-06) Changed-By: Andreas Metzler Description: exim4-base - support files for all Exim MTA (v4) packages exim4-daemon-heavy - Exim MTA (v4) daemon with extended features, including exiscan-ac exim4-daemon-light - lightweight Exim MTA (v4) daemon exim4-dev - header files for the Exim MTA (v4) packages eximon4 - monitor application for the Exim MTA (v4) (X11 interface) Changes: exim4 (4.98.2-1+deb13u3) trixie-security; urgency=high . * Cherry-pick fix for EXIM-Security-2026-05-19.1 from 4.99.4. Security: PROXYv2 parser: reject PROXY frames whose declared payload length is too short for the claimed address family (12 bytes for TCPv4/0x11, 36 bytes for TCPv6/0x21). Previously a frame with family=0x21 and len=0 caused 16 bytes of uninitialized stack to be formatted as the sender's IPv6 address and disclosed in the SMTP greeting banner. Affects configurations with SUPPORT_PROXY and `hosts_proxy` set. Reported by Warisjeet Singh (sin99xx). Checksums-Sha1: 5a07d9c06bee675d0cba9d0f568a8b724a999f17 131636 exim4-base-dbgsym_4.98.2-1+deb13u3_armhf.deb ac86e4b8d28200f328a3f22fe2527cd6b196b6b7 1139632 exim4-base_4.98.2-1+deb13u3_armhf.deb 41fd399e9d9e6aa41511ad2f34b9ef1c4e40f01e 1679540 exim4-daemon-heavy-dbgsym_4.98.2-1+deb13u3_armhf.deb 701dd97fe5fd3007f05623e1ebf2a7832bc258af 637696 exim4-daemon-heavy_4.98.2-1+deb13u3_armhf.deb e23bad9dd610370e7e5b2aa4c192d0dc862eceea 1475164 exim4-daemon-light-dbgsym_4.98.2-1+deb13u3_armhf.deb 8ec7702ae9268b84f0ba536c56c523e8b2a3eba8 582360 exim4-daemon-light_4.98.2-1+deb13u3_armhf.deb 0db0dca58eaa214c3ba6e040827009151bac9b36 36416 exim4-dev_4.98.2-1+deb13u3_armhf.deb f70eba6b3a173a9fa4e6f08c60aae4f31da9f814 11190 exim4_4.98.2-1+deb13u3_armhf-buildd.buildinfo 6d5231ecd88c61f7d848f6643ec4639ba1ce3d2d 138612 eximon4-dbgsym_4.98.2-1+deb13u3_armhf.deb 66ba63d76f335f2f5bf59fb7ded8281124f021fa 67856 eximon4_4.98.2-1+deb13u3_armhf.deb Checksums-Sha256: f5d4a421dc87157c3ca18973a37d390f4a4fcdcd9bd6c54559a1d85c6e963e81 131636 exim4-base-dbgsym_4.98.2-1+deb13u3_armhf.deb 358b6f311edab6f5f3f6d1128e3006c10d17ee858090168c718785024de4ad87 1139632 exim4-base_4.98.2-1+deb13u3_armhf.deb ad2fc6adeb15ab4bf9d5d8286ec69b590a83a6d7e1ed7da8b65eeb10882a007e 1679540 exim4-daemon-heavy-dbgsym_4.98.2-1+deb13u3_armhf.deb ed476bd13ab7413804244fa69f42f4999bc48fc1152dbb70f2657dbac097e0cb 637696 exim4-daemon-heavy_4.98.2-1+deb13u3_armhf.deb 6653f311d50b709475931ed9415e21bad99032e5320c6b6de085874f87dc8e41 1475164 exim4-daemon-light-dbgsym_4.98.2-1+deb13u3_armhf.deb 0c305e48f1108ac772d2c1d5d81dcbe601e3d7d93d02e1f0dc1e4ef0cfb9353e 582360 exim4-daemon-light_4.98.2-1+deb13u3_armhf.deb 591f6eeab047f91fce229577902c4e2d34f1889c816aae88207faf383cc06a26 36416 exim4-dev_4.98.2-1+deb13u3_armhf.deb 9040d4335c1534489247e434ff9a58a93630644cf0d3f1bd26670aa93406524d 11190 exim4_4.98.2-1+deb13u3_armhf-buildd.buildinfo 24f54c14c2e2fd6704c5d8554dc4d120c0910a3351c424534abda38edd11a1e6 138612 eximon4-dbgsym_4.98.2-1+deb13u3_armhf.deb b0ea655ccf855e0838b3bd9855a628a3222170256ca8b66375435a7957807de4 67856 eximon4_4.98.2-1+deb13u3_armhf.deb Files: 18278ab0fe637ef3fd9251e05778bc9f 131636 debug optional exim4-base-dbgsym_4.98.2-1+deb13u3_armhf.deb bd38e0aed94acb29af7eec84b993d9c5 1139632 mail optional exim4-base_4.98.2-1+deb13u3_armhf.deb 0b015e1cd6fdd76e465f9a3a5b600cc6 1679540 debug optional exim4-daemon-heavy-dbgsym_4.98.2-1+deb13u3_armhf.deb 02ca2dfd73642dc63e84fe2863780a04 637696 mail optional exim4-daemon-heavy_4.98.2-1+deb13u3_armhf.deb b625b125c8174efae3ecfc0122b815af 1475164 debug optional exim4-daemon-light-dbgsym_4.98.2-1+deb13u3_armhf.deb 3978db139c9ac0dfaad6c6ef4bbf501d 582360 mail optional exim4-daemon-light_4.98.2-1+deb13u3_armhf.deb 1cd67547a2908c3d3e84da287696783c 36416 mail optional exim4-dev_4.98.2-1+deb13u3_armhf.deb cbdbc616922b1e2b1bf3c3dc6f1439fc 11190 mail standard exim4_4.98.2-1+deb13u3_armhf-buildd.buildinfo c8dd954f933e516d10960b3c2c4409de 138612 debug optional eximon4-dbgsym_4.98.2-1+deb13u3_armhf.deb a7d3e14f92419448b79869cf53dea5e8 67856 mail optional eximon4_4.98.2-1+deb13u3_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBOUsBrtd5lcy6oRfutMAkCxKbL0FAmoYeCAACgkQutMAkCxK bL0vRw/+JrF7qfeSI//JNCDXj9IpGVA5jmXY5DlL1/mmhsjaow4Hz6NE7FdTkiYt PQ+IcgDzrt8gj725G3x0YASazCLevvxF/dAKdAe676+j/XcpeTEnvk7C5aKG6Tqx jy9wpdvXVu6fZhFaDyIYFmasPUOLDzLHlJyg+vyqWHxkCZ0LR9H+Fd6/ci4Kw4Nh M5oV0FraJX74O16h9ftjdQ/wgNMRQObViw9W2mX28VaRaQbnQ1bU1QxUrhw7L/tE N0BWV5ZwTXbDY4p8RaiLCgzMjzfp13fRRDvrdPWhxosdDUsYLu1v5aALoCKjtetd bWwv7xD2RAgqT5J6+2cqVcpS0ozQ/aOkUEfZtEQYm8Y5/2rMR/rFYSKJMsHV04zO ZLkQ9UmNysXr5hC3SuT+kaVdqqsuk8lvErrVlY1NTmXdny/9MqAwHGEXQj0qEXFN Ry2iwjqWw5J2o1j0/V5Y33lNug/JO2xTS2vvbCFIkpO6px2S1HznUBheBu8C9MiL ynx8nxSBO7kTq/+HfsE+L0ljWIThu47KWetXuIFACgd6a9k/1yPgSyqmpmWahWy2 V/D8LkXXUC6QH8sf5eA6DMRH3iyA+FHPKmn17JV8t63ACZVZuE8JO/8CKANjS1WL nlBlzVHWidg9M0teWWLPZjJzPXWiRN6nms6hGZ5Z06J8DqKSer8= =mXdq -----END PGP SIGNATURE-----