CVE-2023-42114: (0Day) Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability
[Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability]
Other sources
Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to disclose information in the context of the service account. . Was ZDI-CAN-17433.
— MITRE
Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to disclose information in the context of the service account. Was ZDI-CAN-17433.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42114?
CVE-2023-42114 is an Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability.
How does CVE-2023-42114 affect Exim?
CVE-2023-42114 allows remote attackers to disclose sensitive information on affected installations of Exim.
Is authentication required to exploit CVE-2023-42114?
No, authentication is not required to exploit CVE-2023-42114.
What is the severity of CVE-2023-42114?
The severity of CVE-2023-42114 is low with a CVSS score of 3.7.
Which versions of Exim are affected by CVE-2023-42114?
Versions 4.90.1-1ubuntu1.10+, 4.93-13ubuntu1.8, 4.95-4ubuntu2.3, 4.96-14ubuntu1.2, 4.82-3ubuntu2.4+, 4.96.1, 4.86.2-2ubuntu2.6+, and some Debian versions are affected by CVE-2023-42114.
How can I fix CVE-2023-42114?
To fix CVE-2023-42114, update Exim to version 4.90.1-1ubuntu1.10+ or apply the appropriate security remediation provided by your distribution.