Critical vulnerabilities have been discovered in Exim, allowing arbitrary code execution on the server.
ZDI (Zero Day Initiative) has published details about three critical vulnerabilities found in the Exim mail server, allowing the execution of arbitrary code on behalf of the server process that opened port 25. No authentication is required for the attack on the server. CVE-2023-42115 — allows unauthorized data to be written outside the designated buffer. This is caused by an input validation error in the SMTP service. CVE-2023-42116 – caused by copying […]
