Buffer overflow in Exim - CVE-2018-6789

 

Buffer overflow in Exim - CVE-2018-6789

Published: February 9, 2018 / Updated: February 20, 2022


Vulnerability identifier: #VU10442
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6789
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists in the SMTP listener due to improper bounds checking. A remote attacker can send a specially crafted message, trigger buffer overflow and execute arbitrary code with privileges of the Exim user.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Exim
Debian Linux
Amazon Linux AMI
Arch Linux
Gentoo Linux
Fedora
Ubuntu
Opensuse
exim (Alpine package)
exim

How to mitigate CVE-2018-6789

Update to version 4.90.1.

exim (Alpine package) - update to 4.90.1-r0
exim - addressed in versions 4.90.1-1.el6, 4.90.1-1.el7, 4.90.1-1.fc26, 4.90.1-1.fc27, 4.90.1-2.el6, 4.90.1-2.el7, 4.90.1-2.fc26, 4.90.1-2.fc27

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins