{"id":172666,"date":"2026-05-19T00:24:49","date_gmt":"2026-05-18T22:24:49","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-exim-4-99-3-ustranena-uyazvimost-pozvolyayushhaya-udalyonnoe-vypolnenie-koda-pri-ispolzovanii-gnutls"},"modified":"2026-05-19T00:24:49","modified_gmt":"2026-05-18T22:24:49","slug":"v-exim-4-99-3-ustranena-uyazvimost-pozvolyayushhaya-udalyonnoe-vypolnenie-koda-pri-ispolzovanii-gnutls","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/v-exim-4-99-3-ustranena-uyazvimost-pozvolyayushhaya-udalyonnoe-vypolnenie-koda-pri-ispolzovanii-gnutls","title":{"rendered":"En Exim 4.99.3 se ha solucionado una vulnerabilidad que permite la ejecuci\u00f3n remota de c\u00f3digo al usar GnuTLS.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Los desarrolladores del servidor de correo Exim han lanzado una versi\u00f3n corregida <strong>Exim 4.99.3<\/strong>, que soluciona una vulnerabilidad en algunas configuraciones del agente de correo. El problema se identifica internamente como <strong>EXIM-Security-2026-05-01.1<\/strong>; en el aviso oficial tambi\u00e9n se menciona como <strong>CVE-TBD<\/strong>.<\/p>\n<p>La vulnerabilidad pertenece a la categor\u00eda <strong>Uso remoto despu\u00e9s de liberar<\/strong> y se manifiesta al analizar el cuerpo del mensaje <strong>BDAT<\/strong> al trabajar con TLS a trav\u00e9s de <strong>GnuTLS<\/strong>. BDAT se utiliza en la extensi\u00f3n SMTP <strong>CHUNKING<\/strong> para transmitir el cuerpo del correo en bloques. Seg\u00fan la descripci\u00f3n de Exim, el error puede ser causado cuando el cliente, durante la transmisi\u00f3n de BDAT, env\u00eda una notificaci\u00f3n TLS close_notify antes de completar la transmisi\u00f3n del cuerpo y luego agrega un byte adicional en la misma conexi\u00f3n TCP.<\/p>\n<p>En tal secuencia, Exim puede escribir datos en un b\u00fafer de memoria que ya ha sido liberado al finalizar la sesi\u00f3n TLS. Esto provoca una corrupci\u00f3n de la memoria din\u00e1mica y puede ser potencialmente explotado para ejecutar c\u00f3digo. El aviso destaca que el atacante solo necesita tener la capacidad de establecer una conexi\u00f3n TLS y utilizar la extensi\u00f3n SMTP <strong>CHUNKING \/ BDAT<\/strong>.<\/p>\n<p>El problema afecta a <strong>Exim 4.97, 4.98, 4.99, 4.99.1 y 4.99.2<\/strong>, pero solo a las compilaciones que han sido compiladas con soporte <strong>GnuTLS<\/strong>. En la documentaci\u00f3n oficial se expresa como configuraciones con USE_GNUTLS=yes; las compilaciones que utilizan <strong>OpenSSL<\/strong> o otras bibliotecas TLS no est\u00e1n afectadas por esta vulnerabilidad. Adem\u00e1s, el aviso de Exim indica espec\u00edficamente que son vulnerables las configuraciones donde se declaran <strong>STARTTLS<\/strong> y <strong>CHUNKING<\/strong>.<\/p>\n<p>La correcci\u00f3n est\u00e1 incluida en <strong>Exim 4.99.3<\/strong>. Seg\u00fan los desarrolladores, el parche garantiza un restablecimiento limpio de la pila de procesamiento de entrada al recibir TLS close_notify durante la transmisi\u00f3n activa de BDAT, lo que previene el uso adicional de punteros obsoletos. No se ha proporcionado otro m\u00e9todo conocido para cerrar completamente el problema, aparte de la actualizaci\u00f3n.<\/p>\n<p>Los desarrolladores de Exim recibieron un informe de error  <strong>el 1 de mayo de 2026<\/strong> de Federico Kirschbaum de <strong>XBOW Security<\/strong>. Tras la verificaci\u00f3n del informe, la correcci\u00f3n se prepar\u00f3 en repositorios cerrados, el 7 de mayo se notific\u00f3 a las distribuciones a trav\u00e9s de una lista de correo cerrada, el 10 de mayo se les dio acceso limitado a las correcciones, y <strong>el 12 de mayo de 2026<\/strong> se public\u00f3 el aviso y la propia versi\u00f3n con la correcci\u00f3n.<\/p>\n<p>Se recomienda a los administradores de servidores de correo que verifiquen la versi\u00f3n de Exim y el backend TLS de la compilaci\u00f3n. Si <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/\"   title=\"servidor\" data-wpil-keyword-link=\"linked\">servidor<\/a> funciona en Exim desde la versi\u00f3n 4.97 hasta la 4.99.2 inclusive, construido con GnuTLS y declara STARTTLS junto con CHUNKING, el proyecto Exim recomienda actualizar lo antes posible a <strong>Exim 4.99.3<\/strong> una versi\u00f3n m\u00e1s nueva. Los c\u00f3digos fuente corregidos est\u00e1n disponibles en la rama exim-4.99+fixes y la etiqueta exim-4.99.3, as\u00ed como en forma de archivos tarball en los sitios de descarga de Exim.<\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18291306\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim \u0432\u044b\u043f\u0443\u0441\u0442\u0438\u043b\u0438 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0440\u0435\u043b\u0438\u0437 Exim 4.99.3, \u0443\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0430\u0433\u0435\u043d\u0442\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u0445\u043e\u0434\u0438\u0442 \u043f\u043e\u0434 \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0438\u043c \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440\u043e\u043c EXIM-Security-2026-05-01.1; \u0432 \u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u043c \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d\u0438\u0438 \u0442\u0430\u043a\u0436\u0435 \u0444\u0438\u0433\u0443\u0440\u0438\u0440\u0443\u0435\u0442 \u043a\u0430\u043a CVE-TBD. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043e\u0442\u043d\u043e\u0441\u0438\u0442\u0441\u044f \u043a \u043a\u043b\u0430\u0441\u0441\u0443 Remote Use-After-Free \u0438 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u0442\u0435\u043b\u0430 \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u044f BDAT \u043f\u0440\u0438 \u0440\u0430\u0431\u043e\u0442\u0435 TLS \u0447\u0435\u0440\u0435\u0437 GnuTLS. BDAT \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 SMTP-\u0440\u0430\u0441\u0448\u0438\u0440\u0435\u043d\u0438\u0438 CHUNKING \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0438 \u0442\u0435\u043b\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-172666","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim \u0432\u044b\u043f\u0443\u0441\u0442\u0438\u043b\u0438 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0440\u0435\u043b\u0438\u0437 Exim 4.99.3, \u0443\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0430\u0433\u0435\u043d\u0442\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/v-exim-4-99-3-ustranena-uyazvimost-pozvolyayushhaya-udalyonnoe-vypolnenie-koda-pri-ispolzovanii-gnutls\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Exim 4.99.3 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 GnuTLS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim \u0432\u044b\u043f\u0443\u0441\u0442\u0438\u043b\u0438 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0440\u0435\u043b\u0438\u0437 Exim 4.99.3, \u0443\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0430\u0433\u0435\u043d\u0442\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/v-exim-4-99-3-ustranena-uyazvimost-pozvolyayushhaya-udalyonnoe-vypolnenie-koda-pri-ispolzovanii-gnutls\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-18T22:24:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-18T22:24:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47En Exim 4.99.3 se ha solucionado una vulnerabilidad que permite la ejecuci\u00f3n remota de c\u00f3digo al utilizar GnuTLS | ProHoster","description":"Los desarrolladores del servidor de correo Exim han lanzado una versi\u00f3n corregida, Exim 4.99.3, que soluciona una vulnerabilidad en algunas configuraciones del agente de correo.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/v-exim-4-99-3-ustranena-uyazvimost-pozvolyayushhaya-udalyonnoe-vypolnenie-koda-pri-ispolzovanii-gnutls","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Exim 4.99.3 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 GnuTLS | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim \u0432\u044b\u043f\u0443\u0441\u0442\u0438\u043b\u0438 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0440\u0435\u043b\u0438\u0437 Exim 4.99.3, \u0443\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0430\u0433\u0435\u043d\u0442\u0430.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/v-exim-4-99-3-ustranena-uyazvimost-pozvolyayushhaya-udalyonnoe-vypolnenie-koda-pri-ispolzovanii-gnutls","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-18T22:24:49+00:00","article:modified_time":"2026-05-18T22:24:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/172666","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=172666"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/172666\/revisions"}],"predecessor-version":[{"id":173168,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/172666\/revisions\/173168"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=172666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=172666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=172666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}