[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Exim



As an Exim user for the past couple of years, I was concerned a bit when
Theo DeRaadt talked about Exim being the only mta without a security audit.
I asked the keeper of the Exim documents, Nigel Metheringham, whether or
not he was aware of anything of the sort, and his reply was:

>I do not know of a security audit for exim.  Feel free to do one.

Okay, so my question is, what does this entail? A simple grep for
keywords in the source? It's standard ansi C. Maybe someone could
enlighten me on what exactly a 'security audit' is.

------------------------
Dana Booth <dana@oz.net>
Tacoma, Wa., USA
------------------------