First published: Thu Oct 26 2023(Updated: )
It was discovered that Exim incorrectly handled validation of user-supplied data, which could lead to memory corruption. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2023-42117) It was discovered that Exim incorrectly handled validation of user-supplied data, which could lead to an out-of-bounds read. An attacker could possibly use this issue to expose sensitive information. (CVE-2023-42119)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/exim4-daemon-heavy | <4.96-17ubuntu2.1 | 4.96-17ubuntu2.1 |
=23.10 | ||
All of | ||
ubuntu/exim4-daemon-light | <4.96-17ubuntu2.1 | 4.96-17ubuntu2.1 |
=23.10 | ||
All of | ||
ubuntu/exim4-daemon-heavy | <4.96-14ubuntu1.3 | 4.96-14ubuntu1.3 |
=23.04 | ||
All of | ||
ubuntu/exim4-daemon-light | <4.96-14ubuntu1.3 | 4.96-14ubuntu1.3 |
=23.04 | ||
All of | ||
ubuntu/exim4-daemon-heavy | <4.95-4ubuntu2.4 | 4.95-4ubuntu2.4 |
=22.04 | ||
All of | ||
ubuntu/exim4-daemon-light | <4.95-4ubuntu2.4 | 4.95-4ubuntu2.4 |
=22.04 | ||
All of | ||
ubuntu/exim4-daemon-heavy | <4.93-13ubuntu1.9 | 4.93-13ubuntu1.9 |
=20.04 | ||
All of | ||
ubuntu/exim4-daemon-light | <4.93-13ubuntu1.9 | 4.93-13ubuntu1.9 |
=20.04 | ||
All of | ||
ubuntu/exim4-daemon-heavy | <4.90.1-1ubuntu1.10+esm2 | 4.90.1-1ubuntu1.10+esm2 |
=18.04 | ||
All of | ||
ubuntu/exim4-daemon-light | <4.90.1-1ubuntu1.10+esm2 | 4.90.1-1ubuntu1.10+esm2 |
=18.04 | ||
All of | ||
ubuntu/exim4-daemon-heavy | <4.86.2-2ubuntu2.6+esm5 | 4.86.2-2ubuntu2.6+esm5 |
=16.04 | ||
All of | ||
ubuntu/exim4-daemon-light | <4.86.2-2ubuntu2.6+esm5 | 4.86.2-2ubuntu2.6+esm5 |
=16.04 | ||
All of | ||
ubuntu/exim4-daemon-heavy | <4.82-3ubuntu2.4+esm7 | 4.82-3ubuntu2.4+esm7 |
=14.04 | ||
All of | ||
ubuntu/exim4-daemon-light | <4.82-3ubuntu2.4+esm7 | 4.82-3ubuntu2.4+esm7 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42117
4.96-17ubuntu2.1
Yes, a remote attacker could possibly use this issue to execute arbitrary code.
Upgrade the exim4-daemon-heavy package to version 4.96-17ubuntu2.1.
You can find more information about this vulnerability at the [Ubuntu Security Advisory](https://ubuntu.com/security/CVE-2023-42117).