Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability
Published May 3, 2024
3.1
LOWCVSS 3.1
EPSS 1.61%
Description
Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. . Was ZDI-CAN-17643.
Affected products
-
- Version exim 4.96-RC0-14-24b8ed847-XXStatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
The vulnerable package Exim is not shipped in any Red Hat products.
References (7)
- https://access.redhat.com/security/cve/CVE-2023-42119 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2241542 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-46578 Advisory
- https://lists.debian.org/debian-lts-announce/2024/10/msg00029.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-42119
- https://www.cve.org/CVERecord?id=CVE-2023-42119
- https://www.zerodayinitiative.com/advisories/ZDI-23-1473/ x_research-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-42119 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2241542 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-46578 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2024/10/msg00029.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-42119 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-42119 | ||
| https://www.zerodayinitiative.com/advisories/ZDI-23-1473/ | x_research-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.