File _patchinfo of Package patchinfo.4780

<patchinfo incident="4780">
  <packager>lmuelle</packager>
  <issue tracker="cve" id="CVE-2016-1531"></issue>
  <issue tracker="bnc" id="968844">VUL-0: CVE-2016-1531: exim: local privilege escalation for set-uid root exim when using perl_startup</issue>
  <category>security</category>
  <rating>important</rating>
  <summary>Security update for exim</summary>
  <description>This update to exim 4.86.2 fixes the following issues:

* CVE-2016-1531: local privilege escalation for set-uid root exim when using 'perl_startup' (boo#968844)

Important: Exim now cleans the complete execution environment by default. This affects Exim and subprocesses such as transports calling other programs. The following new options are supported to adjust this behaviour:
* keep_environment
* add_environment
A warning will be printed upon startup if none of these are configured.

Also includes upstream changes, improvements and bug fixes:
  * Support for using the system standard CA bundle.
  * New expansion items $config_file, $config_dir, containing the file and directory name of the main configuration file. Also $exim_version.
  * New "malware=" support for Avast.
  * New "spam=" variant option for Rspamd.
  * Assorted options on malware= and spam= scanners.
  * A commandline option to write a comment into the logfile.
  * A logging option for slow DNS lookups.
  * New ${env {&lt;variable&gt;}} expansion.
  * A non-SMTP authenticator using information from TLS client certificates.
  * Main option "tls_eccurve" for selecting an Elliptic Curve for TLS.
  * Main option "dns_trust_aa" for trusting your local nameserver at the same level as DNSSEC.
</description>
</patchinfo>
openSUSE Build Service is sponsored by