Memory corruption in Exim - CVE-2017-1000369
Published: June 21, 2017 / Updated: February 5, 2018
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to memory management errors in implementation of various functions under multiple operating systems. A local or remote attacker can overflow group_list[] buffer in Exim main() function to manipulate the heap/stack, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Gentoo Linux
Arch Linux
Debian Linux
Fedora
Ubuntu
Opensuse
exim (Alpine package)
exim
How to mitigate CVE-2017-1000369
exim - addressed in versions 4.89-2.el6, 4.89-2.el7, 4.89-5.fc26
External References
Related Security Bulletins
- Privilege escalation in Exim
- Debian update for exim4
- openSUSE update for exim
- Gentoo update for Exim
- Ubuntu update for Exim
- Arch Linux update for exim
- OpenSUSE Linux update for exim
- Memory corruption in exim (Alpine package)
- Fedora 26 update for exim
- Fedora EPEL 7 update for exim
- Fedora EPEL 6 update for exim