sa-exim vulnerability
A security issue affects these releases of Ubuntu and its
derivatives:
* Ubuntu 16.04 LTS
Summary
Exim SpamAssassin could be made to execute aribitrary code if it
received crafted .cf files/rules.
Software Description
* sa-exim - SpamAssassin filter for Exim
Details
It was discovered that Exim SpamAssassin does not properly handle
configuration strings. An attacker could possibly use this issue
to execute arbitrary code. (CVE-2019-19920)
Update instructions
The problem can be corrected by updating your system to the
following package versions:
Ubuntu 16.04 LTS
sa-exim - 4.2.1-14+deb8u1build0.16.04.1
To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system update will make all the necessary
changes.
References
* CVE-2019-19920
--- Mystic BBS v1.12 A45 (Linux/64)
* Origin: BZ&BZ BBS (21:4/110)