{"id":35011,"date":"2019-10-31T22:01:50","date_gmt":"2019-10-31T19:01:50","guid":{"rendered":"https:\/\/prohoster.info\/blog\/kriticheskaya-uyazvimost-v-exim-pozvolyayushhaya-vypolnit-kod-na-servere-s-pravami-root\/"},"modified":"2019-10-31T22:01:50","modified_gmt":"2019-10-31T19:01:50","slug":"kriticheskaya-uyazvimost-v-exim-pozvolyayushhaya-vypolnit-kod-na-servere-s-pravami-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskaya-uyazvimost-v-exim-pozvolyayushhaya-vypolnit-kod-na-servere-s-pravami-root","title":{"rendered":"Vulnerabilidad cr\u00edtica en Exim que permite ejecutar c\u00f3digo en el servidor con privilegios de root.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>En el servidor de correo Exim <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/06\/05\/4\">se ha detectado<\/a><\/noindex> son cr\u00edticas <noindex><a rel=\"nofollow\" href=\"http:\/\/www.exim.org\/static\/doc\/security\/CVE-2019-10149.txt\">vulnerabilidad<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-10149\">CVE-2019-10149<\/a><\/noindex>), que puede llevar a la ejecuci\u00f3n remota de c\u00f3digo en el servidor con privilegios de root al procesar una solicitud especialmente formateada. Se ha se\u00f1alado la posibilidad de explotaci\u00f3n del problema en las versiones desde 4.87 hasta 4.91 inclusive o en una compilaci\u00f3n con la opci\u00f3n EXPERIMENTAL_EVENT.<\/p>\n<p>En la configuraci\u00f3n predeterminada, un ataque puede realizarse sin complicaciones por un usuario local, ya que se aplica ACL \u00abverify = recipient\u00bb, que realiza comprobaciones adicionales para direcciones externas. Un ataque remoto es posible al cambiar la configuraci\u00f3n, por ejemplo, al operar como un MX secundario para otro dominio, eliminar la ACL \u00abverify = recipient\u00bb o realizar ciertos cambios en local_part_suffix. Un ataque remoto tambi\u00e9n es posible si un atacante puede mantener la conexi\u00f3n con el servidor abierta durante 7 d\u00edas (por ejemplo, enviando un byte por minuto para evitar el corte por tiempo de espera). Tampoco se descarta que existan vectores de ataque m\u00e1s simples para explotar este problema de forma remota.<\/p>\n<p>La vulnerabilidad es causada por una comprobaci\u00f3n incorrecta de la direcci\u00f3n del destinatario en la funci\u00f3n deliver_message(), definida en el archivo \/src\/deliver.c. A trav\u00e9s de la manipulaci\u00f3n del formato de la direcci\u00f3n, un atacante puede conseguir que sus datos se inserten en los argumentos del comando invocado a trav\u00e9s de la funci\u00f3n execv() con privilegios de root. No se requieren t\u00e9cnicas complejas, como las utilizadas en desbordamientos de b\u00fafer o corrupci\u00f3n de memoria, solo es necesaria la simple inserci\u00f3n de caracteres. <\/p>\n<p>El problema est\u00e1 relacionado con el uso de la siguiente construcci\u00f3n para la transformaci\u00f3n de direcciones:<\/p>\n<p>         deliver_localpart = expand_string(<br \/>\n                       string_sprintf(\u00ab${local_part:%s}\u00bb, new-&gt;address));<br \/>\n         deliver_domain = expand_string(<br \/>\n                       string_sprintf(\u00ab${domain:%s}\u00bb, new-&gt;address));<\/p>\n<p>La funci\u00f3n expand_string() es un combinador innecesariamente complejo, que tambi\u00e9n reconoce el comando \u00ab${run{comando argumentos}\u00bb, que lleva a la ejecuci\u00f3n de un procesador externo. As\u00ed, para un ataque dentro de una sesi\u00f3n SMTP, a un usuario local solo le basta enviar un comando del tipo \u2018RCPT TO \u00abusername+${run{\u2026}}@localhost\u00bb\u2019, donde localhost es uno de los hosts en la lista local_domains, y username es el nombre de un usuario local existente. <\/p>\n<p>Si el servidor opera como un rel\u00e9 de correo, solo es necesario enviar un comando remoto \u2018RCPT TO \u00ab${run{\u2026}}@relaydomain.com\u00bb\u2019, donde relaydomain.com es uno de los hosts mencionados en la secci\u00f3n de configuraciones relay_to_domains. Dado que por defecto en exim no se aplica el modo de eliminaci\u00f3n de privilegios (deliver_drop_privilege = false), los comandos enviados a trav\u00e9s de \u00ab${run{\u2026}}\u00bb ser\u00e1n ejecutados con los derechos de root.<\/p>\n<p>Es notable que la vulnerabilidad fue <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Exim\/exim\/commit\/7ea1237c783e380d7bdb86c90b13d8203c7ecf26\">se solucion\u00f3<\/a><\/noindex> en la versi\u00f3n 4.92 lanzada en febrero, sin prestar atenci\u00f3n a que la correcci\u00f3n podr\u00eda conducir a problemas de seguridad. No hay motivos para suponer que los desarrolladores de Exim hayan ocultado deliberadamente la vulnerabilidad, ya que el problema fue resuelto durante <noindex><a rel=\"nofollow\" href=\"https:\/\/bugs.exim.org\/show_bug.cgi?id=2310\">correcciones<\/a><\/noindex> un fallo que ocurre al enviar direcciones incorrectas, y la vulnerabilidad fue descubierta por la empresa Qualys durante una auditor\u00eda de los cambios en Exim. <\/p>\n<p>La correcci\u00f3n para las versiones anteriores, que todav\u00eda se utilizan en las distribuciones, est\u00e1 disponible solo en forma de <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/commit\/d740d2111f189760593a303124ff6b9b1f83453d\">parche<\/a><\/noindex>. Las versiones corregidas para las ramas anteriores que solucionan el problema est\u00e1n programadas para el 11 de junio. Las actualizaciones de paquetes est\u00e1n preparadas para <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-10149\">Debian<\/a><\/noindex>,  <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-10149.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.novell.com\/show_bug.cgi?id=CVE-2019-10149\">EPEL para RHEL\/CentOS<\/a><\/noindex>. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.archlinux.org\/packages\/community\/x86_64\/exim\/\">Arch Linux<\/a><\/noindex> y <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/FEDORA-2019-7b741dcaa4\">Fedora<\/a><\/noindex> ofrecen la versi\u00f3n 4.92, en la cual el problema no se presenta. RHEL y CentOS abordan el problema <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-10149\">no son vulnerables<\/a><\/noindex>, ya que Exim no se encuentra en su repositorio de paquetes est\u00e1ndar.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50819\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 Exim \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-10149), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u0430. \u0412\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u043e\u0442\u043c\u0435\u0447\u0435\u043d\u0430 \u0432 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u0441 4.87 \u043f\u043e 4.91 \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u0438\u043b\u0438 \u043f\u0440\u0438 \u0441\u0431\u043e\u0440\u043a\u0435 \u0441 \u043e\u043f\u0446\u0438\u0435\u0439 EXPERIMENTAL_EVENT. \u0412 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0430\u0442\u0430\u043a\u0430 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0430 \u0431\u0435\u0437 \u043b\u0438\u0448\u043d\u0438\u0445 \u0443\u0441\u043b\u043e\u0436\u043d\u0435\u043d\u0438\u0439 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35011","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 Exim \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskaya-uyazvimost-v-exim-pozvolyayushhaya-vypolnit-kod-na-servere-s-pravami-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Exim, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 Exim \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskaya-uyazvimost-v-exim-pozvolyayushhaya-vypolnit-kod-na-servere-s-pravami-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:01:50+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:01:50+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad cr\u00edtica en Exim que permite ejecutar c\u00f3digo en el servidor con privilegios de root | ProHoster","description":"Se ha identificado una vulnerabilidad cr\u00edtica en el servidor de correo Exim","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskaya-uyazvimost-v-exim-pozvolyayushhaya-vypolnit-kod-na-servere-s-pravami-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Exim, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster","og:description":"\u0412 \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 Exim \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskaya-uyazvimost-v-exim-pozvolyayushhaya-vypolnit-kod-na-servere-s-pravami-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:01:50+00:00","article:modified_time":"2019-10-31T19:01:50+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35011","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 21:28:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:11:30","updated":"2026-01-21 21:28:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/35011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=35011"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/35011\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=35011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=35011"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=35011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}