CVE-2022-37452: Buffer Overflow
Published Aug 7, 2022
·Updated
Exim before 4.95 has a heap-based buffer overflow for the alias list in hostnamelookup in host.c when senderhostname is set.
Affected Software
2 affected components
Exim Exim<4.95
Debian Debian Linux=10.0
Remediation
Patch Available
Patch Available
Event History
Aug 7, 2022
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
Description
Frequently Asked Questions
1
What is CVE-2022-37452?
CVE-2022-37452 is a vulnerability in the Exim email server that allows a heap-based buffer overflow when handling the alias list in host name lookup.
2
What is the severity of CVE-2022-37452?
CVE-2022-37452 has a severity rating of 9.8, which is considered critical.
3
Which software versions are affected by CVE-2022-37452?
Exim versions up to exclusive 4.95 and Debian Linux version 10.0 are affected by CVE-2022-37452.
4
How can I fix CVE-2022-37452?
To fix CVE-2022-37452, it is recommended to update to Exim version 4.95 or higher, or apply the necessary patches provided by the vendor.
5
What are the Common Weakness Enumeration (CWE) identifiers associated with CVE-2022-37452?
CVE-2022-37452 is associated with CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).