{"id":100086,"date":"2021-05-04T22:22:55","date_gmt":"2021-05-04T20:22:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej"},"modified":"2021-05-04T22:22:55","modified_gmt":"2021-05-04T20:22:55","slug":"obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej","title":{"rendered":"Exim 4.94.2 Update Resolves 10 Remote Exploitable Vulnerabilities","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The release of the Exim 4.94.2 mail server addresses 21 vulnerabilities (CVE-2020-28007 to CVE-2020-28026, CVE-2021-27216) discovered by Qualys, collectively known as 21Nails. Ten of these issues can be exploited remotely (including execution of code with root privileges) through manipulation of SMTP commands during interaction with the server.     <\/p>\n<p>All versions of Exim, tracked in Git since 2004, are affected. Working exploit prototypes have been prepared for 4 local vulnerabilities and 3 remote issues. The exploits for the local vulnerabilities (CVE-2020-28007, CVE-2020-28008, CVE-2020-28015, CVE-2020-28012) allow elevating privileges to the root user. Two remote issues (CVE-2020-28020, CVE-2020-28018) enable execution of code with exim user privileges without authentication (which can then lead to root access by exploiting one of the local vulnerabilities).     <\/p>\n<p>The CVE-2020-28021 vulnerability allows remote code execution with root privileges but requires authenticated access (the user must establish an authenticated session, after which they can exploit the vulnerability by manipulating the AUTH parameter in the MAIL FROM command). The issue arises because an attacker can achieve string substitution in the spool file header due to the recording of the authenticated_sender value without proper escaping of special characters (for example, by sending the command \"MAIL FROM: AUTH=Raven+0AReyes\").        <\/p>\n<p>Additionally, it is noted that another remote vulnerability, CVE-2020-28017, is exploitable for executing code with the user privileges of \"exim\" without authentication but requires more than 25 GB of memory. For the remaining 13 vulnerabilities, exploits could potentially also be prepared, but work in this direction has not yet been conducted.        <\/p>\n<p>Exim developers were notified of the issues back in October of last year and spent over 6 months developing fixes. All administrators are strongly recommended to urgently update Exim on their mail servers. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-gdansk\/\"   title=\"servers\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"4516\">servers<\/a> up to version 4.94.2. All Exim versions prior to the release of 4.94.2 have been declared obsolete. The release of the new version was coordinated with distributions that simultaneously published package updates: Ubuntu, Arch Linux, FreeBSD, Debian, SUSE, and Fedora. RHEL and CentOS are not affected, as Exim is not part of their standard package repository (the update is still absent in EPEL).   <\/p>\n<p>Remote vulnerabilities:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2020-28017: Integer overflow in the receive_add_recipient() function;\n<li class=\"l\"> CVE-2020-28020: Integer overflow in the receive_msg() function;\n<li class=\"l\"> CVE-2020-28023: Read out of the allocated buffer area in the smtp_setup_msg() function;\n<li class=\"l\"> CVE-2020-28021: Injection of a newline character into the spool file header;\n<li class=\"l\"> CVE-2020-28022: Write and read out of the allocated buffer area in the extract_option() function;\n<li class=\"l\"> CVE-2020-28026: Truncation and injection of a string in the spool_read_header() function;\n<li class=\"l\"> CVE-2020-28019: Crash when resetting the function pointer after a BDAT error occurs;\n<li class=\"l\"> CVE-2020-28024: Underflow buffer overflows in the smtp_ungetc() function;\n<li class=\"l\"> CVE-2020-28018: Accessing a buffer after it has been freed (use-after-free) in tls-openssl.c\n<li class=\"l\"> CVE-2020-28025: Read out of the allocated buffer area in the pdkim_finish_bodyhash() function.  <\/ul>\n<p>Local vulnerabilities:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2020-28007: Attack via a symbolic link in the Exim log directory;\n<li class=\"l\"> CVE-2020-28008: Attacks on the spool directory;\n<li class=\"l\"> CVE-2020-28014: Arbitrary file creation;\n<li class=\"l\"> CVE-2021-27216: Arbitrary file deletion;\n<li class=\"l\"> CVE-2020-28011: Buffer overflow in the queue_run() function;\n<li class=\"l\"> CVE-2020-28010: Write out of buffer bounds in the main() function;\n<li class=\"l\"> CVE-2020-28013: Buffer overflow in the parse_fix_phrase() function;\n<li class=\"l\"> CVE-2020-28016: Write out of buffer bounds in the parse_fix_phrase() function;\n<li class=\"l\"> CVE-2020-28015: Injection of a newline character into the spool file header;\n<li class=\"l\"> CVE-2020-28012: Absence of the close-on-exec flag for the privileged unnamed channel;\n<li class=\"l\"> CVE-2020-28009: Integer overflow in the get_stdinput() function.  <\/ul>\n<p>          <center>  <iframe loading=\"lazy\" title=\"Exim Mail Server Multiple Vulnerabilities (21Nails)\" src=\"https:\/\/player.vimeo.com\/video\/544783362\" width=\"640\" height=\"360\"><\/iframe>  <\/center><br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55079\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 21 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys \u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c 21Nails. 10 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e (\u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0434\u043b\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root), \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441 SMTP-\u043a\u043e\u043c\u0430\u043d\u0434\u0430\u043c\u0438 \u043f\u0440\u0438 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0432\u0441\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 Exim, \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432 Git [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100086","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 21 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys \u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c 21Nails.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 10 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 21 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys \u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c 21Nails.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-05-04T20:22:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-05-04T20:22:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Exim 4.94.2 update with 10 remotely exploitable vulnerabilities fixed | ProHoster","description":"The release of Exim Mail Server 4.94.2 with fixes for 21 vulnerabilities (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), identified by Qualys and presented under the codename 21Nails.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 10 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 21 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys \u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c 21Nails.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-05-04T20:22:55+00:00","article:modified_time":"2021-05-04T20:22:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100086","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-05-04 20:41:07","updated":"2022-10-05 17:52:30","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/100086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=100086"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/100086\/revisions"}],"predecessor-version":[{"id":164394,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/100086\/revisions\/164394"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=100086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=100086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=100086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}