Exim 4.92.3 has been released, addressing the fourth critical vulnerability of the year.

Published Emergency release of the mail server Exim 4.92.3 addressing yet another critical vulnerability (CVE-2019-16928), potentially allowing remote code execution on the server through a specially crafted string in the EHLO command. The vulnerability occurs after privilege escalation and is limited to executing code with the rights of a non-privileged user under which the incoming message handler operates.

The issue only affects the Exim 4.92 branch (4.92.0, 4.92.1, and 4.92.2) and does not overlap with the vulnerability fixed earlier this month CVE-2019-15846. The vulnerability is caused by a buffer overflow in the function string_vformat(), defined in the string.c file. The demonstrated exploit can cause a crash by passing a long string (several kilobytes) in the EHLO command, but the vulnerability can also be exploited through other commands and potentially used for remote code execution.

No workarounds to mitigate the vulnerability exist, so all users are strongly advised to urgently install the update, apply patch or ensure they are using distribution-provided packages that include fixes for the relevant vulnerabilities. The fix has been released for Ubuntu (affects only the 19.04 branch), Arch Linux, FreeBSD, Debian (affects only Debian 10 Buster) and Alpine. RHEL and CentOS are not affected by the issue as Exim is not included in their default package repository (in EPEL7 the update is still is missing). In SUSE/openSUSE, the vulnerability does not manifest due to the use of Exim version 4.88.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster