{"id":38040,"date":"2019-10-31T22:21:20","date_gmt":"2019-10-31T19:21:20","guid":{"rendered":"https:\/\/prohoster.info\/blog\/propatchil-exim-propatch-eshhe-raz-svezhee-remote-command-execution-v-exim-4-92-v-odin-zapros\/"},"modified":"2021-02-01T11:37:46","modified_gmt":"2021-02-01T09:37:46","slug":"propatchil-exim-propatch-eshhe-raz-svezhee-remote-command-execution-v-exim-4-92-v-odin-zapros","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/propatchil-exim-propatch-eshhe-raz-svezhee-remote-command-execution-v-exim-4-92-v-odin-zapros","title":{"rendered":"Patched Exim \u2014 patch again. Fresh Remote Command Execution in Exim 4.92 in one request","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Patched Exim \u2014 patch again. Fresh Remote Command Execution in Exim 4.92 in one request\" src=\"\/wp-content\/uploads\/2019\/09\/0bb4edaf80bcc0b602bf57c9d3b916be.jpg\" style=\"display:block;margin: 0 auto;\"><\/p>\n<p>Recently, at the beginning of summer, there were widespread calls to update Exim to version 4.92 due to the CVE-2019-10149 vulnerability (<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/455598\/\">Urgently update exim to 4.92 \u2014 active infections ongoing \/ Habr<\/a><\/noindex>). It has recently been discovered that the malware Sustes decided to exploit this vulnerability.<\/p>\n<p>Now all those who updated urgently can once again \"rejoice\": on July 21, 2019, researcher Zerons discovered a critical vulnerability in <strong>the Exim Mail Transfer Agent (MTA) when using TLS<\/strong> for versions from <strong>4.80 to 4.92.1<\/strong> inclusive, allowing remote <strong>code execution with privileged rights<\/strong> (<noindex><a rel=\"nofollow\" href=\"https:\/\/exim.org\/static\/doc\/security\/CVE-2019-15846.txt\">CVE-2019-15846<\/a><\/noindex>).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3 id=\"uyazvimost\">The vulnerability<\/h3>\n<p>The vulnerability exists when using both GnuTLS and OpenSSL libraries when establishing a secure TLS connection.<\/p>\n<p>According to developer Heiko Schlittermann, the Exim configuration file by default does not use TLS, but many distributions create the necessary certificates during installation and include a secure connection. Also, newer versions of Exim set the option <em>tls_advertise_hosts=*<\/em> and generate the necessary certificates.<\/p>\n<blockquote><p>depends on the configuration. Most distros enable it by default, but Exim needs a certificate+key to work as a TLS server. Probably distros create a cert during setup. Newer Exims have the tls_advertise_hosts option defaulting to \"*\" and create a self-signed certificate if none is provided.<\/p><\/blockquote>\n<p>The vulnerability itself lies in the incorrect handling of SNI (Server Name Indication, a technology introduced in 2003 in RFC 3546 to request the correct certificate for the domain name from the client, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/webo\/blog\/327410\/\">TLS SNI standard dissemination \/ WEBO Group Blog \/ Habr<\/a><\/noindex>) during the TLS handshake. An attacker only needs to send an SNI ending with a backslash (\"\") and a null character (\"\").<\/p>\n<p>Researchers at Qualys discovered a bug in the string_printing(tls_in.sni) function, which involves incorrect escaping of \"\". As a result, a backslash is recorded in unescaped form in the print spool header file. Then this file, with privileged rights, is read by the spool_read_header() function, leading to a heap overflow.<\/p>\n<p><strong>It's worth noting that currently Exim developers have created a PoC for the vulnerability with command execution on a remote vulnerable server, but it is not publicly available yet. Due to the ease of exploiting the bug, it\u2019s only a matter of time, and quite a short one at that.<\/strong><\/p>\n<p>A more detailed investigation of the company Qualys can be found. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Exim\/exim\/blob\/master\/doc\/doc-txt\/cve-2019-15846\/qualys.mbx\">here<\/a><\/noindex>.<\/p>\n<p><img decoding=\"async\" alt=\"Patched Exim \u2014 patch again. Fresh Remote Command Execution in Exim 4.92 in one request\" src=\"\/wp-content\/uploads\/2019\/09\/435bc2e3828affdc9be2816036530718.jpg\" style=\"display:block;margin: 0 auto;\"><\/p>\n<p><em>Use of SNI in TLS<\/em><\/p>\n<h3 id=\"kolichestvo-potencialno-uyazvimyh-publichnyh-serverov\">Number of potentially vulnerable public servers<\/h3>\n<p>According to statistics from a major hosting provider <strong>E-Soft Inc<\/strong> as of September 1, version 4.92 is used on more than 70% of rented servers.<\/p>\n<p>Version<br \/>\nNumber of Servers<br \/>\nPercent<\/p>\n<p>4.92.1<br \/>\n6471<br \/>\n1.28%<\/p>\n<p><strong>4.92<\/strong><br \/>\n<strong>376436<\/strong><br \/>\n<strong>74.22%<\/strong><\/p>\n<p>4.91<br \/>\n58179<br \/>\n11.47%<\/p>\n<p>4.9<br \/>\n5732<br \/>\n1.13%<\/p>\n<p>4.89<br \/>\n10700<br \/>\n2.11%<\/p>\n<p>4.87<br \/>\n14177<br \/>\n2.80%<\/p>\n<p>4.84<br \/>\n9937<br \/>\n1.96%<\/p>\n<p>Other versions<br \/>\n25568<br \/>\n5.04%<\/p>\n<p><em>Statistics from E-Soft Inc<\/em><\/p>\n<p>If you turn to the search engine <noindex><a rel=\"nofollow\" href=\"https:\/\/www.shodan.io\/\"><strong>Shodan<\/strong><\/a><\/noindex>, out of 5,250,000 in the server database:<\/p>\n<ul>\n<li>about 3,500,000 use Exim 4.92 (about 1,380,000 using SSL\/TLS);<\/li>\n<li>more than 74,000 use 4.92.1 (about 25,000 using SSL\/TLS).<\/li>\n<\/ul>\n<p>Thus, there are approximately <strong>1.5 million<\/strong>.<\/p>\n<p><img decoding=\"async\" alt=\"Patched Exim \u2014 patch again. Fresh Remote Command Execution in Exim 4.92 in one request\" src=\"\/wp-content\/uploads\/2019\/09\/53dac3e4d5d4a127f522a17ae1633084.jpg\" style=\"display:block;margin: 0 auto;\"><\/p>\n<p><em>Searching for Exim servers in Shodan<\/em><\/p>\n<h3 id=\"zaschita\">Protection<\/h3>\n<ul>\n<li>The simplest, but not recommended option is not to use TLS, which will lead to the transmission of emails in plain text.<\/li>\n<li>A more preferable way to avoid exploitation of the vulnerability would be to upgrade to version <noindex><a rel=\"nofollow\" href=\"http:\/\/exim.org\/index.html\">Exim Internet Mailer 4.92.2<\/a><\/noindex>.<\/li>\n<li>If upgrading or installing a patched version is not possible, you can set ACL in the Exim configuration for the option <strong>acl_smtp_mail<\/strong> with the following rules:\n<pre><code class=\"plaintext\"># to be prepended to your mail acl (the ACL referenced\n# by the acl_smtp_mail main config option)\ndeny    condition = ${if eq{}{${substr{-1}{1}{$tls_in_sni}}}}\ndeny    condition = ${if eq{}{${substr{-1}{1}{$tls_in_peerdn}}}}<\/code><\/pre>\n<\/li>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/jetinfosystems\/blog\/467089\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043e\u0432\u0441\u0435\u043c \u043d\u0435\u0434\u0430\u0432\u043d\u043e, \u0432 \u043d\u0430\u0447\u0430\u043b\u0435 \u043b\u0435\u0442\u0430, \u043f\u043e\u044f\u0432\u0438\u043b\u0438\u0441\u044c \u043c\u0430\u0441\u0441\u043e\u0432\u044b\u0435 \u043f\u0440\u0438\u0437\u044b\u0432\u044b \u043a \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044e Exim \u0434\u043e \u0432\u0435\u0440\u0441\u0438\u0438 4.92 \u0438\u0437-\u0437\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CVE-2019-10149 (\u0421\u0440\u043e\u0447\u043d\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u044f\u0439\u0442\u0435 exim \u0434\u043e 4.92 \u2014 \u0438\u0434\u0451\u0442 \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0435 \u0437\u0430\u0440\u0430\u0436\u0435\u043d\u0438\u0435 \/ \u0425\u0430\u0431\u0440). \u0410 \u043d\u0430 \u0434\u043d\u044f\u0445 \u0432\u044b\u044f\u0441\u043d\u0438\u043b\u043e\u0441\u044c, \u0447\u0442\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441 Sustes \u0440\u0435\u0448\u0438\u043b \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u044d\u0442\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e. \u0422\u0435\u043f\u0435\u0440\u044c \u0432\u0441\u0435 \u044d\u043a\u0441\u0442\u0440\u0435\u043d\u043d\u043e \u043e\u0431\u043d\u043e\u0432\u0438\u0432\u0448\u0438\u0435\u0441\u044f \u043c\u043e\u0433\u0443\u0442 \u043e\u043f\u044f\u0442\u044c \u00ab\u043f\u043e\u0440\u0430\u0434\u043e\u0432\u0430\u0442\u044c\u0441\u044f\u00bb: 21 \u0438\u044e\u043b\u044f 2019 \u0433. \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c Zerons \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":28554,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-38040","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/propatchil-exim-propatch-eshhe-raz-svezhee-remote-command-execution-v-exim-4-92-v-odin-zapros\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u043e\u043f\u0430\u0442\u0447\u0438\u043b Exim \u2014 \u043f\u0440\u043e\u043f\u0430\u0442\u0447\u044c \u0435\u0449\u0435 \u0440\u0430\u0437. \u0421\u0432\u0435\u0436\u0435\u0435 Remote Command Execution \u0432 Exim 4.92 \u0432 \u043e\u0434\u0438\u043d \u0437\u0430\u043f\u0440\u043e\u0441 | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/propatchil-exim-propatch-eshhe-raz-svezhee-remote-command-execution-v-exim-4-92-v-odin-zapros\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:21:20+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-02-01T09:37:46+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Patched Exim \u2014 patch it again. Fresh Remote Command Execution in Exim 4.92 in one request | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/propatchil-exim-propatch-eshhe-raz-svezhee-remote-command-execution-v-exim-4-92-v-odin-zapros","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u043e\u043f\u0430\u0442\u0447\u0438\u043b Exim \u2014 \u043f\u0440\u043e\u043f\u0430\u0442\u0447\u044c \u0435\u0449\u0435 \u0440\u0430\u0437. \u0421\u0432\u0435\u0436\u0435\u0435 Remote Command Execution \u0432 Exim 4.92 \u0432 \u043e\u0434\u0438\u043d \u0437\u0430\u043f\u0440\u043e\u0441 | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/propatchil-exim-propatch-eshhe-raz-svezhee-remote-command-execution-v-exim-4-92-v-odin-zapros","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:21:20+00:00","article:modified_time":"2021-02-01T09:37:46+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38040","title":null,"description":"","keywords":"","keyphrases":null,"primary_term":null,"canonical_url":"","og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 20:14:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:16:23","updated":"2026-01-23 20:14:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=38040"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38040\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/28554"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=38040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=38040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=38040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}