PublicDateAtUSN: 2016-12-16 Candidate: CVE-2016-9963 PublicDate: 2017-02-01 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9963 http://www.openwall.com/lists/oss-security/2016/12/16/1 https://www.exim.org/static/doc/CVE-2016-9963.txt https://ubuntu.com/security/notices/USN-3164-1 Description: Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages. Ubuntu-Description: Notes: Bugs: https://bugs.exim.org/show_bug.cgi?id=1996 Priority: medium Discovered-by: Bjoern Jacke Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N [5.9 MEDIUM] Patches_exim4: upstream: https://github.com/Exim/exim/commit/87cb4a166c47b57df48c2918e47801d77639fbb0 (master) upstream: https://github.com/Exim/exim/commit/46672dc8be913fb02f0aa822d79c590fac276182 (4.80.1) upstream: https://github.com/Exim/exim/commit/fd3961f062107c5c64016cff0331fd2cf1181cdd (4.80.1 test) upstream: https://github.com/Exim/exim/commit/be2b8e517f4946d2ad0cb0100e7b078cb4d9b65f (4.87) upstream: https://github.com/Exim/exim/commit/31c02defdc5118834e801d4fe8f11c1d9b5ebadf (4.86) upstream: https://github.com/Exim/exim/commit/f915863397aa037a437155da67424d094821a23b (4.86) upstream_exim4: released (4.87.1,4.88) precise_exim4: released (4.76-3ubuntu3.4) trusty_exim4: released (4.82-3ubuntu2.2) trusty/esm_exim4: released (4.82-3ubuntu2.2) vivid/stable-phone-overlay_exim4: DNE vivid/ubuntu-core_exim4: DNE xenial_exim4: released (4.86.2-2ubuntu2.1) esm-infra/xenial_exim4: released (4.86.2-2ubuntu2.1) yakkety_exim4: released (4.87-3ubuntu1.1) devel_exim4: released (4.88-5ubuntu1)