Buffer overflow in Exim - CVE-2023-42117

 

Buffer overflow in Exim - CVE-2023-42117

Published: September 28, 2023 / Updated: October 1, 2023


Vulnerability identifier: #VU81254
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-42117
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the smtp service. A remote attacker can send specially crafted data to the server, trigger memory corruption and execute arbitrary code on the target system.


Affected software

Exim
Amazon Linux AMI
Gentoo Linux
Fedora
Ubuntu
SmartFabric Storage Software
exim4-daemon-light (Ubuntu package)
exim4-daemon-heavy (Ubuntu package)
exim
exim4 (Ubuntu package)
mail-mta/exim

How to mitigate CVE-2023-42117

Install update from vendor's website.

Exim - addressed in versions 4.96.1, 4.97
SmartFabric Storage Software - update to 1.4.3
exim4-daemon-light (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.9, 4.95-4ubuntu2.4, 4.96-14ubuntu1.3, 4.96-17ubuntu2.1
exim4-daemon-heavy (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.9, 4.95-4ubuntu2.4, 4.96-14ubuntu1.3, 4.96-17ubuntu2.1
exim - update to 4.92-1.39
exim4 (Ubuntu package) - update to 4.95-4ubuntu2.10
exim - addressed in versions 4.96.1-1.el7, 4.96.1-1.el8, 4.96.1-1.el9, 4.96.1-1.fc37, 4.96.1-1.fc38, 4.96.1-1.fc39, 4.96.1-1.fc40
mail-mta/exim - update to 4.97.1

External References

Related Security Bulletins