Use-after-free in Exim - CVE-2022-3559

 

Use-after-free in Exim - CVE-2022-3559

Published: November 24, 2022


Vulnerability identifier: #VU69579
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3559
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in the regex handler. A remote attacker can send specially crafted data to the mail server, trigger a use-after-free error and perform a denial of service (DoS) attack.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Exim
Amazon Linux AMI
Fedora
Ubuntu
openEuler
SmartFabric Storage Software
exim4-base (Ubuntu package)
exim4-daemon-light (Ubuntu package)
exim4-daemon-heavy (Ubuntu package)
exim
exim-pgsql
exim-greylist
exim-mysql
exim-debuginfo
exim-mon
exim-clamav
exim-debugsource

How to mitigate CVE-2022-3559

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

SmartFabric Storage Software - update to 1.4.3
exim4-base (Ubuntu package) - addressed in versions 4.90.1-1ubuntu1.10, 4.93-13ubuntu1.7, 4.95-4ubuntu2.2, 4.96-3ubuntu1.1
exim4-daemon-light (Ubuntu package) - addressed in versions 4.90.1-1ubuntu1.10, 4.93-13ubuntu1.7, 4.95-4ubuntu2.2, 4.96-3ubuntu1.1
exim4-daemon-heavy (Ubuntu package) - addressed in versions 4.90.1-1ubuntu1.10, 4.93-13ubuntu1.7, 4.95-4ubuntu2.2, 4.96-3ubuntu1.1
exim - update to 4.92-1.34
exim-pgsql - update to 4.96-3
exim-greylist - update to 4.96-3
exim-mysql - update to 4.96-3
exim-debuginfo - update to 4.96-3
exim-mon - update to 4.96-3
exim-clamav - update to 4.96-3
exim-debugsource - update to 4.96-3
exim - update to 4.96-3
exim - addressed in versions 4.96-3.el7, 4.96-3.el8, 4.96-3.el9, 4.96-4.fc35, 4.96-4.fc36, 4.96-4.fc37

External References

Related Security Bulletins