First published: Thu Sep 28 2023(Updated: )
[Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability]
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Exim Exim | ||
ubuntu/exim4 | <4.96.1 | 4.96.1 |
ubuntu/exim4 | <4.93-13ubuntu1.8 | 4.93-13ubuntu1.8 |
ubuntu/exim4 | <4.95-4ubuntu2.3 | 4.95-4ubuntu2.3 |
ubuntu/exim4 | <4.96-14ubuntu1.2 | 4.96-14ubuntu1.2 |
ubuntu/exim4 | <4.96-17ubuntu2 | 4.96-17ubuntu2 |
debian/exim4 | 4.92-8+deb10u6 4.92-8+deb10u9 4.94.2-7+deb11u2 4.96-15+deb12u4 4.97-5 4.97-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42115 is an (0Day) Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability.
CVE-2023-42115 allows remote attackers to execute arbitrary code on affected installations of Exim.
No, authentication is not required to exploit CVE-2023-42115.
CVE-2023-42115 has a severity value of 9.8, which is critical.
To fix CVE-2023-42115 on Ubuntu, update the Exim4 package to version 4.93-13ubuntu1.8, 4.95-4ubuntu2.3, 4.96-14ubuntu1.2, or 4.96.1 depending on the specific Ubuntu release.