Hi Andreas,

On Fri, Sep 25, 2026 at 11:31:39AM +0200, Andreas Metzler wrote:
> On 2026-09-24 Salvatore Bonaccorso <[email protected]> wrote:
> > On Thu, Sep 24, 2026 at 09:59:32PM +0200, Salvatore Bonaccorso wrote:
> > > On Thu, Sep 24, 2026 at 07:02:00PM +0200, Andreas Metzler wrote:
> [...]
> > > > the second one (CVE-2026-94055 / GnuTLS) only applies to versions >=
> > > > 4.99, i.e. stable and earlier are fine. tls_early_banner was not
> > > > available in earlier releases.
> > > 
> > > Alright, thanks will update the tracker.
> 
> > Hmm ist that correct? The upstream advisory say:
> 
> > - Exim versions from 4.98 up to and including 4.100 are affected.
> > - The installation must be built with GnuTLS 3.6.4 or later, and configured
> >    to accept TLS-on-connect.
> > - The configuration must enable the tls_early_banner_hosts option
> >    (a non-default setting).
> 
> Hello Salvatore,
> 
> I have asked upstream to confirm/reject this.
> https://lists.exim.org/lurker/message/20260925.044831.5cb31b15.en.html
> 
> Propopsed patch attched.

Thanks for the debdiff. Please go ahead with the upload to
security-master.

Regards,
Salvatore

Reply via email to