New RCE Vulnerability Impacts Nearly Half of the Internet's Email Servers

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12Lu2uMUte=AyaP_L_oxWHbCj=yoVmztRxA+qq0ZM1FDDw@mail.gmail.com>
'A critical remote command execution (RCE) security flaw impacts over
half of the Internet's email servers, security researchers from Qualys
have revealed today. The vulnerability affects Exim, a mail transfer
agent (MTA), which is software that runs on email servers to relay
emails from senders to recipients. According to a June 2019 survey of
all mail servers visible on the Internet, 57% (507,389) of all email
servers run Exim -- although different reports would put the number of
Exim installations at ten times that number, at 5.4 million.

In a security alert shared with ZDNet earlier today, Qualys, a
cyber-security firm specialized in cloud security and compliance, said
it found a very dangerous vulnerability in Exim installations running
versions 4.87 to 4.91. The vulnerability is described as a remote
command execution -- different, but just as dangerous as a remote code
execution flaw -- that lets a local or remote attacker run commands on
the Exim server as root. Qualys said the vulnerability can be
exploited instantly by a local attacker that has a presence on an
email server, even with a low-privileged account. lBut the real danger
comes from remote hackers exploiting the vulnerability, who can scan
the internet for vulnerable servers, and take over systems.

The vulnerability was patched with Exim 4.92, on February 10, 2019,
"but at the time the Exim team released v4.92, they didn't know they
fixed a major security hole," reports ZDNet.

"This was only recently discovered by the Qualys team while auditing
older Exim versions. Now, Qualys researchers are warning Exim users to
update to the 4.92 version to avoid having their servers taken over by
attackers."'

-- source: https://it.slashdot.org/story/19/06/06/0046234

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.