Re: [oss-security] Exim CVE-2019-16928 RCE using a heap-based buffer overflow
Heiko Schlittermann via Exim-announce <[email protected]> Sun, 29 Sep 2019 01:20:24 +0200
| Newsgroups | gmane.mail.exim.announce |
|---|---|
| Organization | schlittermann -- internet & unix support |
| Message-ID | <20190928232024.GK16334__35208.4293191851$1569713669$gmane$org@jumper.schlittermann.de> |
--===============0549662518== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="0ywUhQCikZ2Y3PNw" Content-Disposition: inline --0ywUhQCikZ2Y3PNw Content-Type: text/plain; charset=utf-8 Content-Disposition: inline ** Exim 4.92.3 released (security release) ** CVE ID: CVE-2019-16928 Date: 2019-09-27 (CVE assigned) Version(s): from 4.92 up to and including 4.92.2 Reporter: QAX-A-TEAM <[email protected]> Reference: https://bugs.exim.org/show_bug.cgi?id=2449 Issue: Heap-based buffer overflow in string_vformat, remote code execution seems to be possible Conditions to be vulnerable =========================== All versions from (and including) 4.92 up to (and including) 4.92.2 are vulnerable. Details ======= There is a heap-based buffer overflow in string_vformat (string.c). The currently known exploit uses a extraordinary long EHLO string to crash the Exim process that is receiving the message. While at this mode of operation Exim already dropped its privileges, other paths to reach the vulnerable code may exist. Mitigation ========== There is - beside updating the server - no known mitigation. Fix === Download and build the fixed version 4.92.3 Tarballs: https://ftp.exim.org/pub/exim/exim4/ Git: https://github.com/Exim/exim.git (mirror) git://git.exim.org/exim.git - tag exim-4.92.3 - branch exim-4.92.3+fixes The tagged commit is the officially released version. The +fixes branch isn't officially maintained, but contains the security fix *and* useful fixes. The tarballs, the Git tag, and the Git commits are signed with my GPG key (same as I used to sign this mail.) If you can't install the above versions, ask your package maintainer for a version containing the backported fix. On request and depending on our resources we will support you in backporting the fix. (Please note, the Exim project officially doesn't support versions prior the current stable version.) Timeline ========= - 2019-09-27 Report as Bug 2499 - 2019-09-28 Announcement to exim-maintainers, oss-security - 2019-09-28 Release 4.92.3, Release-Announcements to exim-{announce,users,maintainers}, oss-security --0ywUhQCikZ2Y3PNw Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEE0L/WueylaUpvFJ3Or0zGdqa2wUIFAl2P6rcACgkQr0zGdqa2 wUL1DQf9HM4pvPtoWBLFN/WMwuO72WPPeBl1FyHi3a1z/ZplT5ZvMbRSFAi3xhrs 4lhibAsYn6kaC4Cn82gbcxDoOcURFDKTRROpXWTV6QH0aDAV4KWamHjpfUE8IPMw TcRDuQcd9UsZ3W/+zznBS5j6ojlN9YdXWUpKHuNFLUoV7t2WgP45gk4aKNhMGLal WeR53eu2T8zLdP57PyJlewYcduBxDvLyxq0BofOl62iyKOvKhoYwXbPfHj5OE+7p cJECsO1Ozujpg0gtkr1lYrWe4jipJOxBDCBmnpeocVhlx0uM7k4TxQRydLD9J2mf l9YvRuAjKulaCQPJ2/nifr+bGHFbEg== =wTZT -----END PGP SIGNATURE----- --0ywUhQCikZ2Y3PNw-- --===============0549662518== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ## List details at https://lists.exim.org/mailman/listinfo/exim-announce Exim details at http://www.exim.org/ ## --===============0549662518==--