Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.nz

2 replies

lemmy.world

While ZDI reported the vulnerability to the Exim team in June 2022 and resent info on the flaw at the vendor's request in May 2023, the developers failed to provide an update on their patch progress.

Yikes. Sitting on a critical RCE in internet exposed server software for a year. That's a great way to destroy trust in a project.

12
phxreply

One of the first things I tended to do after building a new Debian etc system was uninstall Exim. Vulnerabilities aside is kinda crap to maintain versus e.g Postfix

2

You reached the end

Millions of Exim mail servers exposed to zero-day RCE attacks | Spyke