On Wed, 2019-09-11 at 12:54 +0100, John Winters wrote:
On 11/09/2019 12:51, Andy Smith wrote:
[snip]
As far as I am aware every Exim ever released
that is configured to
do TLS and deliver locally is vulnerable to remote root compromise
by this bug.
Thank you - that's the exact question to which I was seeking an
answer.
John
...not that I'm considering not upgrading or anything. I was just
curious.
+1 - as always, Andy is totally on top of things. Thank you for sharing
these details!
I'll look into deliver_drop_privilege option.
Conrad