{"id":37876,"date":"2019-10-31T22:20:17","date_gmt":"2019-10-31T19:20:17","guid":{"rendered":"https:\/\/prohoster.info\/blog\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim\/"},"modified":"2019-10-31T22:20:17","modified_gmt":"2019-10-31T19:20:17","slug":"raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim","title":{"rendered":"Se han revelado detalles de una vulnerabilidad cr\u00edtica en Exim","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/ftp.exim.org\/pub\/exim\/exim4\/\">Publicado<\/a><\/noindex> lanzamiento correctivo <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Exim\/exim\/releases\/tag\/exim-4.92.2\">Exim 4.92.2<\/a><\/noindex> con correcci\u00f3n cr\u00edtica <noindex><a rel=\"nofollow\" href=\"http:\/\/exim.org\/static\/doc\/security\/CVE-2019-15846.txt\">una vulnerabilidad<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-15846\">CVE-2019-15846<\/a><\/noindex>), que en la configuraci\u00f3n predeterminada puede llevar a la ejecuci\u00f3n remota de c\u00f3digo por un atacante con privilegios de root. El problema se manifiesta solo cuando se habilita el soporte para TLS y se explota mediante el env\u00edo de un certificado de cliente especialmente preparado o un valor modificado en SNI. La vulnerabilidad <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/blob\/2600301ba6:\/doc\/doc-txt\/cve-2019-15846\/qualys.mbx\">se ha detectado<\/a><\/noindex>  fue descubierta por Qualys.<\/p>\n<p>Problema <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-15846\">hay<\/a><\/noindex> en el manejador de escape de caracteres especiales en la cadena (<noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/blob\/cf84d126bc:\/src\/src\/string.c#l217\">string_interpret_escape()<\/a><\/noindex> de string.c) y se debe a que el car\u00e1cter &#8216;&#092;&#8217; al final de la cadena se interpreta antes del car\u00e1cter nulo (&#8216;&#092;0&#8217;) y lo escapa. Al escapar, la secuencia &#8216;&#092;&#8217; y el siguiente c\u00f3digo nulo al final de la cadena se procesan como un solo s\u00edmbolo y el puntero se desplaza a los datos m\u00e1s all\u00e1 de la cadena, que se tratan como su continuaci\u00f3n. <\/p>\n<p>El c\u00f3digo que llama a string_interpret_escape() asigna un b\u00fafer basado en el tama\u00f1o real, y el puntero resultante queda en el \u00e1rea fuera de los l\u00edmites del b\u00fafer. Por lo tanto, al intentar procesar la cadena de entrada, se produce una situaci\u00f3n de lectura de datos desde un \u00e1rea fuera de los l\u00edmites del b\u00fafer asignado, y el intento de escritura de la cadena desescapada puede llevar a escribir fuera del b\u00fafer.<\/p>\n<p>En la configuraci\u00f3n predeterminada, la vulnerabilidad puede ser explotada mediante el env\u00edo de datos especialmente formateados en SNI al establecer una conexi\u00f3n segura con el servidor. El problema tambi\u00e9n puede ser explotado mediante la modificaci\u00f3n de los valores peerdn en configuraciones configuradas para la autenticaci\u00f3n mediante certificaci\u00f3n de cliente, o al importar certificados. El ataque a trav\u00e9s de SNI y peerdn es posible desde el lanzamiento de <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=33981\">Exim 4.80<\/a><\/noindex>, donde se aplic\u00f3 la funci\u00f3n string_unprinting() para desescapar el contenido de peerdn y SNI.<\/p>\n<p>Se ha preparado un prototipo de exploit para un ataque a trav\u00e9s de SNI, que funciona en arquitecturas i386 y amd64 en sistemas Linux con Glibc. El exploit utiliza un solapamiento de datos en el \u00e1rea de la pila, lo que provoca una reescritura de la memoria donde se almacena el nombre del archivo de registro. El nombre del archivo se reemplaza por &#171;\\\/..\\\/..\\\/..\\\/..\\\/..\\\/..\\\/..\\\/..\\\/etc\\\/passwd&#187;. Luego, se sobreescribe la variable con la direcci\u00f3n del remitente, que se guarda primero en el registro, lo que permite a\u00f1adir un nuevo usuario al sistema. <\/p>\n<p>Las actualizaciones de paquetes que corrigen la vulnerabilidad han sido lanzadas por las distribuciones <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-15846\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-15846.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/FEDORA-2019-467fcbb10a\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.novell.com\/show_bug.cgi?id=CVE-2019-15846\">SUSE\/openSUSE<\/a><\/noindex> y <noindex><a rel=\"nofollow\" href=\"http:\/\/www.vuxml.org\/freebsd\/61db9b88-d091-11e9-8d41-97657151f8c2.html\">FreeBSD<\/a><\/noindex>. RHEL y CentOS sobre el problema <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-15846\">no son vulnerables<\/a><\/noindex>, ya que Exim no est\u00e1 incluido en su repositorio de paquetes oficial (en <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.fedoraproject.org\/archives\/list\/epel-package-announce@lists.fedoraproject.org\/\">EPEL<\/a><\/noindex> actualizaci\u00f3n <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1749838\">(env\u00edo de datos).<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/apps.fedoraproject.org\/packages\/exim\/builds\/\">se ha formado<\/a><\/noindex>, pero por ahora <noindex><a rel=\"nofollow\" href=\"https:\/\/dl.fedoraproject.org\/pub\/epel\/7\/x86_64\/Packages\/e\/\">no est\u00e1 alojado<\/a><\/noindex> en un repositorio p\u00fablico). En el c\u00f3digo de Exim, el problema se resuelve con una l\u00ednea de <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/blobdiff\/165e7dd1823da93e43b41bcc9941a6a9088ba11f..2600301ba6dbac5c9d640c87007a07ee6dcea1f4:\/src\/src\/string.c\">parche<\/a><\/noindex>, que desactiva la acci\u00f3n de escape de la barra invertida si se encuentra al final de la l\u00ednea.<\/p>\n<p>Como soluci\u00f3n alternativa para mitigar la vulnerabilidad, se puede desactivar el soporte para TLS o agregar en la<br \/>\nsecci\u00f3n ACL &#171;acl_smtp_mail&#187;:\n<\/p>\n<p>    deny    condition = ${if eq{&#092;&#092;}{${substr{-1}{1}{$tls_in_sni}}}}<br \/>\n    deny    condition = ${if eq{&#092;&#092;}{${substr{-1}{1}{$tls_in_peerdn}}}}<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51435\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a Exim 4.92.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-15846), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u0440\u0438 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438 TLS \u0438 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u0447\u0435\u0440\u0435\u0437 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 \u0438\u043b\u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f \u0432 SNI. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0435 \u044d\u043a\u0440\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043f\u0435\u0446\u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37876","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a Exim.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0441\u0442\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Exim | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a Exim.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:20:17+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:20:17+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Detalles revelados sobre una vulnerabilidad cr\u00edtica en Exim | ProHoster","description":"Se ha publicado una versi\u00f3n corregida de Exim.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0441\u0442\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Exim | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a Exim.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:20:17+00:00","article:modified_time":"2019-10-31T19:20:17+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37876","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 19:36:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:19:22","updated":"2026-01-23 19:36:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/37876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=37876"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/37876\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=37876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=37876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=37876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}