Eenos updates Exim to version 4.98 to fix CVE-2024-39929, a critical 9.1 CVSS vulnerability. Update your server now to stay secure and prevent email exploits.
A critical security vulnerability has been identified in the Exim mail transfer agent, potentially allowing attackers to send malicious attachments to users' inboxes.
According to the U.S. National Vulnerability Database (NVD), "Exim through 4.97.1 misparses a multiline RFC 2231 header filename, allowing remote attackers to bypass the $mime_filename extension-blocking protection mechanism and possibly deliver executable attachments to users' mailboxes."
The Eenos hosting control panel has been updated to include Exim package version 4.98. If you have automatic updates enabled, this update has already been applied to your servers. If not, we strongly recommend updating your server as soon as possible.
To verify the Exim version on your server, use the following command:
# exim --version
Experience the power of Eenos with a free trial today!