{"id":38530,"date":"2019-10-31T22:24:20","date_gmt":"2019-10-31T19:24:20","guid":{"rendered":"https:\/\/prohoster.info\/blog\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti\/"},"modified":"2019-10-31T22:24:20","modified_gmt":"2019-10-31T19:24:20","slug":"opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti","title":{"rendered":"Pubblicato Exim 4.92.3 con la correzione della quarta vulnerabilit\u00e0 critica dell'anno.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/lists.exim.org\/lurker\/message\/20190928.232024.589b2ef5.en.html\">Pubblicato<\/a><\/noindex> uscita urgente del server di posta <noindex><a rel=\"nofollow\" href=\"https:\/\/www.exim.org\/\">Exim 4.92.3<\/a><\/noindex> con la risoluzione di un altro <noindex><a rel=\"nofollow\" href=\"http:\/\/exim.org\/static\/doc\/security\/CVE-2019-16928.txt\">vulnerabilit\u00e0 critica<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-16928\">CVE-2019-16928<\/a><\/noindex>), che potrebbe consentire l'esecuzione remota di codice sul server tramite la trasmissione di una stringa appositamente formattata nel comando EHLO. La vulnerabilit\u00e0 si manifesta nella fase successiva al ripristino dei privilegi ed \u00e8 limitata all'esecuzione di codice con i diritti di un utente non privilegiato, sotto il quale viene eseguito il gestore dei messaggi in arrivo.<\/p>\n<p>Il problema si presenta solo nella versione Exim 4.92 (4.92.0, 4.92.1 e 4.92.2) e non si sovrappone alla vulnerabilit\u00e0 risolta all'inizio del mese <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51435\">CVE-2019-15846<\/a><\/noindex>. La vulnerabilit\u00e0 \u00e8 causata da un overflow del buffer nella funzione <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/blob\/cf84d126bc:\/src\/src\/string.c#l1287\">string_vformat()<\/a><\/noindex>, definita nel file string.c. La dimostrazione <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/patch\/478effbfd9c3cc5a627fc671d4bf94d13670d65f\">un exploit<\/a><\/noindex> permette di causare un crash tramite l'invio di una lunga stringa (alcuni kilobyte) nel comando EHLO, ma la vulnerabilit\u00e0 pu\u00f2 essere sfruttata anche tramite altri comandi e pu\u00f2 potenzialmente essere utilizzata per eseguire codice.<\/p>\n<p>Non ci sono workaround per bloccare la vulnerabilit\u00e0, quindi si raccomanda a tutti gli utenti di installare urgentemente l'aggiornamento, applicare <noindex><a rel=\"nofollow\" href=\"https:\/\/git.exim.org\/exim.git\/patch\/478effbfd9c3cc5a627fc671d4bf94d13670d65f\">patch<\/a><\/noindex> o verificare di utilizzare i pacchetti forniti dalle distribuzioni in cui sono state implementate le correzioni delle vulnerabilit\u00e0 attuali. La correzione \u00e8 stata rilasciata per <noindex><a rel=\"nofollow\" href=\"https:\/\/usn.ubuntu.com\/4141-1\/\">Ubuntu<\/a><\/noindex> (riguarda solo la versione 19.04), <noindex><a rel=\"nofollow\" href=\"https:\/\/www.archlinux.org\/packages\/?q=exim\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"http:\/\/www.vuxml.org\/freebsd\/e917caba-e291-11e9-89f1-152fed202bb7.html\">FreeBSD<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-16928\">Debian<\/a><\/noindex> (riguarda solo Debian 10 Buster) e <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?search=exim\">Fedora<\/a><\/noindex>. RHEL e CentOS non sono interessati al problema, poich\u00e9 Exim non fa parte del loro repository di pacchetti standard (in <noindex><a rel=\"nofollow\" href=\"https:\/\/fedoraproject.org\/wiki\/EPEL\">EPEL7<\/a><\/noindex> l'aggiornamento \u00e8 ancora <noindex><a rel=\"nofollow\" href=\"https:\/\/dl.fedoraproject.org\/pub\/epel\/7\/SRPMS\/Packages\/e\/\">\u00e8 assente<\/a><\/noindex>). In SUSE\/openSUSE la vulnerabilit\u00e0 non si manifesta a causa dell'utilizzo della versione Exim 4.88.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51590\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u0442\u0440\u0435\u043d\u043d\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.92.3 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043e\u0447\u0435\u0440\u0435\u0434\u043d\u043e\u0439 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-16928), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0447\u0435\u0440\u0435\u0437 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0432 \u043a\u043e\u043c\u0430\u043d\u0434\u0435 EHLO. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430 \u0441\u0442\u0430\u0434\u0438\u0438 \u043f\u043e\u0441\u043b\u0435 \u0441\u0431\u0440\u043e\u0441\u0430 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 \u0438 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0430 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435\u043c \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0434 \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043f\u043e\u0441\u0442\u0443\u043f\u0430\u044e\u0449\u0438\u0445 \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u0439. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u0432\u0435\u0442\u043a\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38530","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u0442\u0440\u0435\u043d\u043d\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d Exim 4.92.3 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u043e\u0439 \u0437\u0430 \u0433\u043e\u0434 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u0442\u0440\u0435\u043d\u043d\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:24:20+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:24:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Pubblicato Exim 4.92.3 con la risoluzione della quarta vulnerabilit\u00e0 critica dell'anno | ProHoster","description":"Pubblicata un'uscita urgente del server di posta","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d Exim 4.92.3 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u043e\u0439 \u0437\u0430 \u0433\u043e\u0434 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u0442\u0440\u0435\u043d\u043d\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/opublikovan-exim-4-92-3-s-ustraneniem-chetvyortoj-za-god-kriticheskoj-uyazvimosti","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:24:20+00:00","article:modified_time":"2019-10-31T19:24:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38530","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 22:24:45","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:07:40","updated":"2026-01-23 22:24:45","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/38530","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=38530"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/38530\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=38530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=38530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=38530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}