It was discovered that Exim incorrectly handled certain command line
options. A local attacker could possibly use this issue to access files
outside of the spool area.

It was discovered that Exim incorrectly handled string expansion in
.local files. A local attacker could possibly use this issue to escalate
privileges.