{"id":38530,"date":"2019-10-31T22:24:20","date_gmt":"2019-10-31T19:24:20","guid":{"rendered":"https:\/\/prohoster.info\/blog\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti\/"},"modified":"2019-10-31T22:24:20","modified_gmt":"2019-10-31T19:24:20","slug":"opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti","title":{"rendered":"Exim 4.92.3 a \u00e9t\u00e9 publi\u00e9 avec la correction de la quatri\u00e8me vuln\u00e9rabilit\u00e9 critique de l'ann\u00e9e.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/lists.exim.org\/lurker\/message\/20190928.232024.589b2ef5.en.html\">Publi\u00e9<\/a><\/noindex> publication urgente du serveur de messagerie <noindex><a rel=\"nofollow\" href=\"https:\/\/www.exim.org\/\">Exim 4.92.3<\/a><\/noindex> avec correction d'une <noindex><a rel=\"nofollow\" href=\"http:\/\/exim.org\/static\/doc\/security\/CVE-2019-16928.txt\">vuln\u00e9rabilit\u00e9 critique<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-16928\">CVE-2019-16928<\/a><\/noindex>), permettant potentiellement l'ex\u00e9cution de code \u00e0 distance sur le serveur via l'envoi d'une cha\u00eene sp\u00e9cialement format\u00e9e dans la commande EHLO. La vuln\u00e9rabilit\u00e9 se manifeste apr\u00e8s la remise des privil\u00e8ges et est limit\u00e9e \u00e0 l'ex\u00e9cution de code avec les droits d'utilisateur non privil\u00e9gi\u00e9 sous lequel le gestionnaire des messages entrants s'ex\u00e9cute.<\/p>\n<p>Le probl\u00e8me ne se manifeste que dans la branche Exim 4.92 (4.92.0, 4.92.1 et 4.92.2) et ne se croise pas avec la vuln\u00e9rabilit\u00e9 corrig\u00e9e en d\u00e9but de mois. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51435\">CVE-2019-15846<\/a><\/noindex>. La vuln\u00e9rabilit\u00e9 est caus\u00e9e par un d\u00e9passement de tampon dans la fonction <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/blob\/cf84d126bc:\/src\/src\/string.c#l1287\">string_vformat()<\/a><\/noindex>, d\u00e9finie dans le fichier string.c. La d\u00e9monstration <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/patch\/478effbfd9c3cc5a627fc671d4bf94d13670d65f\">un exploit<\/a><\/noindex> permet de provoquer un crash en envoyant une longue cha\u00eene (plusieurs kilooctets) dans la commande EHLO, mais la vuln\u00e9rabilit\u00e9 peut \u00e9galement \u00eatre exploit\u00e9e via d'autres commandes et pourrait potentiellement \u00eatre utilis\u00e9e pour organiser l'ex\u00e9cution de code.<\/p>\n<p>Il n'existe pas de contournement pour bloquer cette vuln\u00e9rabilit\u00e9, il est donc recommand\u00e9 \u00e0 tous les utilisateurs d'installer d'urgence la mise \u00e0 jour, d'appliquer <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/patch\/478effbfd9c3cc5a627fc671d4bf94d13670d65f\">un patch<\/a><\/noindex> ou de s'assurer d'utiliser les paquets fournis par les distributions, dans lesquels les correctifs pour les vuln\u00e9rabilit\u00e9s actuelles ont \u00e9t\u00e9 int\u00e9gr\u00e9s. Le correctif a \u00e9t\u00e9 publi\u00e9 pour <noindex><a rel=\"nofollow\" href=\"https:\/\/usn.ubuntu.com\/4141-1\/\">Ubuntu<\/a><\/noindex> (affecte uniquement la branche 19.04), <noindex><a rel=\"nofollow\" href=\"https:\/\/www.archlinux.org\/packages\/?q=exim\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"http:\/\/www.vuxml.org\/freebsd\/e917caba-e291-11e9-89f1-152fed202bb7.html\">FreeBSD<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-16928\">Debian<\/a><\/noindex> (affecte uniquement Debian 10 Buster) et <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?search=exim\">Fedora<\/a><\/noindex>. RHEL et CentOS ne sont pas concern\u00e9s par ce probl\u00e8me, car Exim ne fait pas partie de leur r\u00e9f\u00e9rentiel de paquets standard (dans <noindex><a rel=\"nofollow\" href=\"https:\/\/fedoraproject.org\/wiki\/EPEL\">EPEL7<\/a><\/noindex> la mise \u00e0 jour est actuellement <noindex><a rel=\"nofollow\" href=\"https:\/\/dl.fedoraproject.org\/pub\/epel\/7\/SRPMS\/Packages\/e\/\">absente<\/a><\/noindex>). Dans SUSE\/openSUSE, la vuln\u00e9rabilit\u00e9 ne se manifeste pas en raison de l'utilisation de la branche Exim 4.88.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51590\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u0442\u0440\u0435\u043d\u043d\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.92.3 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043e\u0447\u0435\u0440\u0435\u0434\u043d\u043e\u0439 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-16928), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0447\u0435\u0440\u0435\u0437 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0432 \u043a\u043e\u043c\u0430\u043d\u0434\u0435 EHLO. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430 \u0441\u0442\u0430\u0434\u0438\u0438 \u043f\u043e\u0441\u043b\u0435 \u0441\u0431\u0440\u043e\u0441\u0430 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 \u0438 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0430 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435\u043c \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0434 \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043f\u043e\u0441\u0442\u0443\u043f\u0430\u044e\u0449\u0438\u0445 \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0439. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u0432\u0435\u0442\u043a\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38530","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u0442\u0440\u0435\u043d\u043d\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d Exim 4.92.3 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u043e\u0439 \u0437\u0430 \u0433\u043e\u0434 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u0442\u0440\u0435\u043d\u043d\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:24:20+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:24:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Publication d'Exim 4.92.3 avec correction de la quatri\u00e8me vuln\u00e9rabilit\u00e9 critique de l'ann\u00e9e | ProHoster","description":"Publication urgente du serveur de messagerie","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d Exim 4.92.3 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u043e\u0439 \u0437\u0430 \u0433\u043e\u0434 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u0442\u0440\u0435\u043d\u043d\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:24:20+00:00","article:modified_time":"2019-10-31T19:24:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38530","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 22:24:45","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:07:40","updated":"2026-01-23 22:24:45","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/38530","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=38530"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/38530\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=38530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=38530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=38530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}