Use-after-free in Exim - CVE-2022-3559
Published: November 24, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in the regex handler. A remote attacker can send specially crafted data to the mail server, trigger a use-after-free error and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Amazon Linux AMI
Fedora
Ubuntu
openEuler
SmartFabric Storage Software
exim4-base (Ubuntu package)
exim4-daemon-light (Ubuntu package)
exim4-daemon-heavy (Ubuntu package)
exim
exim-pgsql
exim-greylist
exim-mysql
exim-debuginfo
exim-mon
exim-clamav
exim-debugsource
How to mitigate CVE-2022-3559
exim4-base (Ubuntu package) - addressed in versions 4.90.1-1ubuntu1.10, 4.93-13ubuntu1.7, 4.95-4ubuntu2.2, 4.96-3ubuntu1.1
exim4-daemon-light (Ubuntu package) - addressed in versions 4.90.1-1ubuntu1.10, 4.93-13ubuntu1.7, 4.95-4ubuntu2.2, 4.96-3ubuntu1.1
exim4-daemon-heavy (Ubuntu package) - addressed in versions 4.90.1-1ubuntu1.10, 4.93-13ubuntu1.7, 4.95-4ubuntu2.2, 4.96-3ubuntu1.1
exim - update to 4.92-1.34
exim-pgsql - update to 4.96-3
exim-greylist - update to 4.96-3
exim-mysql - update to 4.96-3
exim-debuginfo - update to 4.96-3
exim-mon - update to 4.96-3
exim-clamav - update to 4.96-3
exim-debugsource - update to 4.96-3
exim - update to 4.96-3
exim - addressed in versions 4.96-3.el7, 4.96-3.el8, 4.96-3.el9, 4.96-4.fc35, 4.96-4.fc36, 4.96-4.fc37
External References
- https://git.exim.org/exim.git/commit/4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2
- https://bugs.exim.org/show_bug.cgi?id=2915
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WFHLZVHNNO2GWYP5EA4TZQZ5O4GVPARR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMQ6OCKPNPBPSD37YR4FOWV2R54M2UEP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EIH4W5R7SHTUEQFWWKB4TUO5YFZX64KV/
Related Security Bulletins
- Denial of service in Exim
- Ubuntu update for exim4
- Amazon Linux AMI update for exim
- openEuler 22.03 LTS SP3 update for exim
- openEuler 22.03 LTS SP4 update for exim
- Fedora 37 update for exim
- Fedora 36 update for exim
- Fedora 35 update for exim
- Fedora EPEL 9 update for exim
- Fedora EPEL 8 update for exim
- Fedora EPEL 7 update for exim
- Dell SmartFabric Storage Software update for third-party components