CVE-2023-42116: (0Day) Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability
[Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability]
Other sources
Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17515.
— MITRE
Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-17515.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42116?
CVE-2023-42116 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Exim.
Is authentication required to exploit CVE-2023-42116?
No, authentication is not required to exploit this vulnerability.
What is the severity of CVE-2023-42116?
CVE-2023-42116 has a severity rating of 8.1 (high).
Which versions of Exim are affected by CVE-2023-42116?
Versions 4.90.1-1ubuntu1.10+ to 4.96.1 of Exim are affected by CVE-2023-42116.
How do I fix CVE-2023-42116?
To fix CVE-2023-42116, update your Exim installation to version 4.90.1-1ubuntu1.10+ or higher.