Three critical vulnerabilities in Exim allow for remote code execution on the server.

The Zero Day Initiative (ZDI) has disclosed information about unpatched (0-day) vulnerabilities (CVE-2023-42115, CVE-2023-42116, CVE-2023-42117) in the Exim mail server, allowing remote code execution on the server with the privileges of the process that accepts connections on port 25. No authentication is required to carry out the attack.

The first vulnerability (CVE-2023-42115) is caused by an error in the SMTP service and is related to the lack of proper checks on data received from the user during the SMTP session and used for calculating the buffer size. As a result, an attacker can achieve controlled writing of their data into memory outside of the allocated buffer.

The second vulnerability (CVE-2023-42116) is present in the NTLM request handler and is caused by copying user-provided data into a fixed-size buffer without necessary size checks of the data being written.

The third vulnerability (CVE-2023-42117) is present in the SMTP process that accepts connections on TCP port 25 and is caused by the lack of input validation, which can lead to user-provided data being written to memory outside of the allocated buffer.

The vulnerabilities are marked as 0-day, meaning they remain unpatched, but the ZDI report claims that Exim developers were notified of the issues in advance. The last change to the Exim codebase was made two days ago, and it is unclear when the issues will be resolved (distributors have not yet reacted as the information was disclosed without details just hours ago). Currently, Exim developers are preparing to release a new version 4.97, but there is no exact information on when it will be published. The sole method of protection mentioned so far is limiting access to the SMTP service based on Exim.

In addition to the critical vulnerabilities mentioned above, information has also been revealed about several less severe issues:

  • CVE-2023-42118 — an integer overflow in the libspf2 library, manifesting during SPF macro parsing. The vulnerability allows for remote corruption of memory contents and could potentially be exploited to execute arbitrary code. server.
  • CVE-2023-42114 — an error that leads to reading memory outside the buffer in the NTLM handler. This issue may result in the leakage of memory content from the process handling network requests.
  • CVE-2023-42119 — a vulnerability in the dnsdb handler that leads to the leakage of memory content from the smtp process.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster