Critical vulnerabilities have been discovered in Exim, allowing arbitrary code execution on the server.

ZDI (Zero Day Initiative) has published information about three critical vulnerabilities found in the Exim mail server, allowing arbitrary code execution on behalf of the server process that opens port 25. No authentication is required for the attack.

  1. CVE-2023-42115 — allows the recording of data outside the allocated buffer. Caused by input validation errors in the SMTP service.
  2. CVE-2023-42116 – caused by copying user data into a fixed-size buffer without checking the required size.
  3. CVE-2023-42117 – also caused by insufficient input validation on the SMTP service port 25.

The vulnerabilities are marked as 0-day, meaning they are not being fixed, although according to ZDI, Exim developers have long been warned about their existence. A fix may be included in version 4.97 of the server, but this is not guaranteed.

To protect against these vulnerabilities, it is currently recommended to restrict access to SMTP on port 25.

UPD. It seems that the situation is not as dire. These vulnerabilities are local in nature. They do not work if the server does not use NTLM and EXTERNAL authentication, is not secured behind a proxy, does not use potentially dangerous DNS servers, and does not have SPF in the ACL. Learn more…

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster