Exim 4.99.5 Drops AI-Discovered Security Patches for Mail Servers

Published by

Exim 4.99.5 has been released to address two privilege escalation flaws in mail server versions 4.82 through 4.99.4, including a high-severity directory traversal issue and a medium-severity vulnerability related to .forward file expansion. The unique aspect of this release is the credit given to AI training data for discovering these bugs, highlighting the increasing role of automated analysis in identifying security issues. Users are urged to upgrade immediately and review their configurations to mitigate potential exploits. The release underscores the importance of maintaining legacy systems like Exim, which powers a significant percentage of the world's email infrastructure



Exim 4.99.5 Drops AI-Discovered Security Patches for Mail Servers

Exim 4.99.5 dropped today to patch two privilege escalation flaws affecting mail server versions 4.82 through 4.99.4. The high-severity bug allows directory traversal through queue name arguments, while the medium-severity issue exploits .forward file expansion when force_command is enabled on a pipe transport. In a first for the project, the advisory credits "authors ingested as the training corpus," highlighting how automated LLM analysis is increasingly surfacing legacy security issues. Administrators should upgrade immediately and audit their pipe transport configurations to eliminate the exploit window.

Exim 4.99.5 Drops AI-Discovered Security Patches for Mail Servers @ Linux Compatible