Re: [bitfolk] 21 critical Exim security issues need addressi…

Top Page
Author: Andy Smith
Date:  
To: users
Subject: Re: [bitfolk] 21 critical Exim security issues need addressing

Reply to this message
gpg: Signature made Fri May 7 11:26:20 2021 UTC
gpg: using DSA key 0E4236CB52951E14536066222099B64CBF15490B
gpg: Good signature from "Andy Smith <andy@strugglers.net>" [unknown]
gpg: aka "Andrew James Smith <andy@strugglers.net>" [unknown]
gpg: aka "Andy Smith (UKUUG) <andy.smith@ukuug.org>" [unknown]
gpg: aka "Andy Smith (BitFolk Ltd.) <andy@bitfolk.com>" [unknown]
gpg: aka "Andy Smith (Linux User Groups UK) <andy@lug.org.uk>" [unknown]
gpg: aka "Andy Smith (Cernio Technology Cooperative) <andy.smith@cernio.com>" [unknown]
Hello,

On Fri, May 07, 2021 at 10:44:15AM +0100, Nigel Rantor via users wrote:
> Thank you so much for this.


No worries, but if this did come as news to anyone then I recommend
enabling automatic security upgrades - or at least notifications of
them.

On Debian/Ubuntu you can install the unattended-upgrades package to
automatically do the upgrades, and/or apticron to email you about
available upgrades.

Also apt-;listchanges mails you the changelogs after upgrades have
taken place.

The only reason I've mailed announce@ this time is that the last two
times there were remote root exploits in Exim, some people did not
patch for whatever reason and were compromised.

I understand it's not actually that hard to convert a simple Debian
Exim setup to Postfix so if anyone would like tow rite a wiki
article or blog about it that would be most welcome!

Cheers,
Andy

--
https://bitfolk.com/ -- No-nonsense VPS hosting