Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
BID:10290
Info
Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
| Bugtraq ID: | 10290 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0399 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery is credited to Georgi Guninski. |
| Vulnerable: |
University of Cambridge Exim-tls 3.35 University of Cambridge Exim 3.35 |
| Not Vulnerable: | |
Discussion
Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
Exim has been reported prone to a remotely exploitable stack-based buffer overrun vulnerability.
This is exposed if sender verification has been enabled in the agent and may be triggered by a malicious e-mail. Exploitation may permit execution of arbitrary code in the content of the mail transfer agent.
This issue is reported in exist in Exim 3.35. Earlier versions may also be affected.
It should be noted that the vulnerable functionality is not enabled in the default install, though some Linux/Unix distributions that ship the software may enable it.
Exim has been reported prone to a remotely exploitable stack-based buffer overrun vulnerability.
This is exposed if sender verification has been enabled in the agent and may be triggered by a malicious e-mail. Exploitation may permit execution of arbitrary code in the content of the mail transfer agent.
This issue is reported in exist in Exim 3.35. Earlier versions may also be affected.
It should be noted that the vulnerable functionality is not enabled in the default install, though some Linux/Unix distributions that ship the software may enable it.
Exploit / POC
Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
Proof-of-concept code that triggers a denial of service is available at the following location:
http://www.guninski.com/exim1.html
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
An exploit (maxim.c) is available by newroot & nopfish:
Proof-of-concept code that triggers a denial of service is available at the following location:
http://www.guninski.com/exim1.html
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
An exploit (maxim.c) is available by newroot & nopfish:
Solution / Fix
Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
Solution:
Debian has released advisory DSA-501-1 dealing with this and other issues. Please see the referenced web advisory for more information and details on obtaining fixes.
Debian has released advisory DSA 502-1 dealing with this issue for their Exim-tls packages. Please see the referenced web advisory for more information and details on obtaining fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
University of Cambridge Exim-tls 3.35
University of Cambridge Exim 3.35
Solution:
Debian has released advisory DSA-501-1 dealing with this and other issues. Please see the referenced web advisory for more information and details on obtaining fixes.
Debian has released advisory DSA 502-1 dealing with this issue for their Exim-tls packages. Please see the referenced web advisory for more information and details on obtaining fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
University of Cambridge Exim-tls 3.35
-
Debian exim-tls_3.35-3woody2_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_alpha.deb -
Debian exim-tls_3.35-3woody2_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_arm.deb -
Debian exim-tls_3.35-3woody2_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_hppa.deb -
Debian exim-tls_3.35-3woody2_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_i386.deb -
Debian exim-tls_3.35-3woody2_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_ia64.deb -
Debian exim-tls_3.35-3woody2_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_m68k.deb -
Debian exim-tls_3.35-3woody2_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_mips.deb -
Debian exim-tls_3.35-3woody2_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_mipsel.deb -
Debian exim-tls_3.35-3woody2_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_powerpc.deb -
Debian exim-tls_3.35-3woody2_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_s390.deb -
Debian exim-tls_3.35-3woody2_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_sparc.deb
University of Cambridge Exim 3.35
-
Debian exim-tls_3.35-3woody2_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_alpha.deb -
Debian exim-tls_3.35-3woody2_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_arm.deb -
Debian exim-tls_3.35-3woody2_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_hppa.deb -
Debian exim-tls_3.35-3woody2_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_i386.deb -
Debian exim-tls_3.35-3woody2_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_ia64.deb -
Debian exim-tls_3.35-3woody2_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_m68k.deb -
Debian exim-tls_3.35-3woody2_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_mips.deb -
Debian exim-tls_3.35-3woody2_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_mipsel.deb -
Debian exim-tls_3.35-3woody2_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_powerpc.deb -
Debian exim-tls_3.35-3woody2_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_s390.deb -
Debian exim-tls_3.35-3woody2_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/e/exim-tls/exim-tls_3.35- 3woody2_sparc.deb
References
Exim Sender Verification Remote Stack Buffer Overrun Vulnerability
References:
References:
- DSA-501-1 exim -- buffer overflow (Debian)
- Exim Homepage (Exim)
- Exim sender_verify stack overflow exploit (CORE Security)