Eugeny / ajenti-v

Virtual Hosting addon for Ajenti
ajenti.org/#product-ajenti-v
MIT License
225 stars 80 forks source link

Exim log (and LogWatch) polluted with useless messages related to CVE-2016-1531 #226

Open mikestp27 opened 8 years ago

mikestp27 commented 8 years ago

With latest Exim4 security update (CVE-2016-1531), the exim4 mainlog file, and LogWatch reports are polluted with several messages like this one: Warning: purging the environment. Suggested action: use keep_environment. With ajenti-v, exim4 runs under Debian-exim user and the environment is empty by default; so it should be safe to simply add the missing config setting to avoid those useless log messages. I fixed it locally by adding those 2 lines in my "Custom Configuration" box for Exim settings.

# http://exim.org/static/doc/CVE-2016-1531.txt
keep_environment =

It would be great if this could be added to the exim template.