{"id":37876,"date":"2019-10-31T22:20:17","date_gmt":"2019-10-31T19:20:17","guid":{"rendered":"https:\/\/prohoster.info\/blog\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim\/"},"modified":"2019-10-31T22:20:17","modified_gmt":"2019-10-31T19:20:17","slug":"raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim","title":{"rendered":"Des d\u00e9tails sur une vuln\u00e9rabilit\u00e9 critique dans Exim ont \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9s","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/ftp.exim.org\/pub\/exim\/exim4\/\">Publi\u00e9<\/a><\/noindex> version corrective <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Exim\/exim\/releases\/tag\/exim-4.92.2\">Exim 4.92.2<\/a><\/noindex> avec correction d'une issue critique <noindex><a rel=\"nofollow\" href=\"http:\/\/exim.org\/static\/doc\/security\/CVE-2019-15846.txt\">une vuln\u00e9rabilit\u00e9<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-15846\">CVE-2019-15846<\/a><\/noindex>), qui dans la configuration par d\u00e9faut peut permettre l'ex\u00e9cution de code \u00e0 distance par un attaquant avec des droits root. Le probl\u00e8me se manifeste uniquement lorsque le support TLS est activ\u00e9 et est exploit\u00e9 via l'envoi d'un certificat client sp\u00e9cialement form\u00e9 ou d'une valeur modifi\u00e9e dans le SNI. La vuln\u00e9rabilit\u00e9 <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/blob\/2600301ba6:\/doc\/doc-txt\/cve-2019-15846\/qualys.mbx\">une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 identifi\u00e9e<\/a><\/noindex>  a \u00e9t\u00e9 signal\u00e9e par Qualys.<\/p>\n<p>Le probl\u00e8me <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-15846\">est pr\u00e9sent<\/a><\/noindex> dans le gestionnaire d'\u00e9chappement des caract\u00e8res sp\u00e9ciaux dans la cha\u00eene (<noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/blob\/cf84d126bc:\/src\/src\/string.c#l217\">string_interpret_escape()<\/a><\/noindex> de string.c) et est caus\u00e9e par le fait que le symbole \u2018\u2019 \u00e0 la fin de la cha\u00eene est interpr\u00e9t\u00e9 avant le caract\u00e8re nul (\u2018\u2019) et l'\u00e9chappe. Lors de l'\u00e9chappement, la s\u00e9quence \u2018\u2019 et le code nul suivant \u00e0 la fin de la cha\u00eene sont trait\u00e9s comme un seul symbole et le pointeur se d\u00e9place vers des donn\u00e9es au-del\u00e0 de la cha\u00eene, qui sont trait\u00e9es comme sa continuation. <\/p>\n<p>Le code appelant string_interpret_escape() alloue un tampon sous le flux, bas\u00e9 sur la taille r\u00e9elle, et le pointeur se retrouve dans une zone en dehors des limites du tampon. Par cons\u00e9quent, lors du traitement de la cha\u00eene d'entr\u00e9e, une situation de lecture de donn\u00e9es en dehors des limites du tampon allou\u00e9 se produit, et la tentative d'\u00e9criture de la cha\u00eene d\u00e9s\u00e9chapp\u00e9e peut entra\u00eener une \u00e9criture au-del\u00e0 du tampon.<\/p>\n<p>Dans la configuration par d\u00e9faut, la vuln\u00e9rabilit\u00e9 peut \u00eatre exploit\u00e9e via l'envoi de donn\u00e9es sp\u00e9cialement form\u00e9es dans le SNI lors de l'\u00e9tablissement d'une connexion s\u00e9curis\u00e9e au serveur. Le probl\u00e8me peut \u00e9galement \u00eatre exploit\u00e9 en modifiant les valeurs peerdn dans les configurations r\u00e9gl\u00e9es pour l'authentification par certificat client, ou lors de l'importation de certificats. L'attaque via SNI et peerdn est possible \u00e0 partir de la version <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=33981\">Exim 4.80<\/a><\/noindex>, o\u00f9 la fonction string_unprinting() a \u00e9t\u00e9 utilis\u00e9e pour d\u00e9s\u00e9chapper le contenu de peerdn et SNI.<\/p>\n<p>Un prototype d'exploit a \u00e9t\u00e9 pr\u00e9par\u00e9 pour une attaque via SNI, fonctionnant sur des architectures i386 et amd64 dans des syst\u00e8mes Linux avec Glibc. L'exploit utilise un superposition de donn\u00e9es sur la zone de tas, entra\u00eenant l'\u00e9crasement de la m\u00e9moire o\u00f9 est stock\u00e9 le nom du fichier journal. Le nom du fichier est remplac\u00e9 par \u2018\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/passwd\u2019. Ensuite, la variable avec l'adresse de l'exp\u00e9diteur, qui est d'abord enregistr\u00e9e dans le journal, est r\u00e9\u00e9crite, ce qui permet d'ajouter un nouvel utilisateur au syst\u00e8me. <\/p>\n<p>Des mises \u00e0 jour de paquets corrigeant la vuln\u00e9rabilit\u00e9 ont \u00e9t\u00e9 publi\u00e9es par les distributions <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-15846\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-15846.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/FEDORA-2019-467fcbb10a\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.novell.com\/show_bug.cgi?id=CVE-2019-15846\">SUSE\/openSUSE<\/a><\/noindex> et <noindex><a rel=\"nofollow\" href=\"http:\/\/www.vuxml.org\/freebsd\/61db9b88-d091-11e9-8d41-97657151f8c2.html\">FreeBSD<\/a><\/noindex>. RHEL et CentOS concernant ce probl\u00e8me. <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-15846\">n'est pas soumis<\/a><\/noindex>, car Exim n'est pas inclus dans leur d\u00e9p\u00f4t de packages standard (dans <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.fedoraproject.org\/archives\/list\/epel-package-announce@lists.fedoraproject.org\/\">EPEL<\/a><\/noindex> une mise \u00e0 jour <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1749838\">d\u00e9j\u00e0<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/apps.fedoraproject.org\/packages\/exim\/builds\/\">a \u00e9t\u00e9 \u00e9labor\u00e9e<\/a><\/noindex>, mais pour l'instant <noindex><a rel=\"nofollow\" href=\"https:\/\/dl.fedoraproject.org\/pub\/epel\/7\/x86_64\/Packages\/e\/\">non mis<\/a><\/noindex> dans le d\u00e9p\u00f4t public). Dans le code d'Exim, le probl\u00e8me est corrig\u00e9 par une ligne de code <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/blobdiff\/165e7dd1823da93e43b41bcc9941a6a9088ba11f..2600301ba6dbac5c9d640c87007a07ee6dcea1f4:\/src\/src\/string.c\">patch<\/a><\/noindex>, qui d\u00e9sactive l'effet d'\u00e9chappement du backslash s'il se trouve \u00e0 la fin de la ligne.<\/p>\n<p>Comme solution de contournement pour bloquer la vuln\u00e9rabilit\u00e9, il est possible de d\u00e9sactiver la prise en charge de TLS ou d'ajouter \u00e0<br \/>\nsection ACL \u2018acl_smtp_mail\u2019:\n<\/p>\n<p>    deny    condition = ${if eq{\\}{${substr{-1}{1}{$tls_in_sni}}}}<br \/>\n    deny    condition = ${if eq{\\}{${substr{-1}{1}{$tls_in_peerdn}}}}<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51435\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a Exim 4.92.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-15846), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u0440\u0438 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438 TLS \u0438 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u0447\u0435\u0440\u0435\u0437 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 \u0438\u043b\u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f \u0432 SNI. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0435 \u044d\u043a\u0440\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043f\u0435\u0446\u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37876","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a Exim.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0441\u0442\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Exim | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a Exim.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:20:17+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:20:17+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 D\u00e9tails r\u00e9v\u00e9l\u00e9s sur une vuln\u00e9rabilit\u00e9 critique dans Exim | ProHoster","description":"Une version corrective d'Exim a \u00e9t\u00e9 publi\u00e9e.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0441\u0442\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Exim | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a Exim.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/raskryty-podrobnosti-kriticheskoj-uyazvimosti-v-exim","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:20:17+00:00","article:modified_time":"2019-10-31T19:20:17+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37876","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 19:36:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:19:22","updated":"2026-01-23 19:36:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/37876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=37876"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/37876\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=37876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=37876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=37876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}