USN-6455-1: Exim vulnerabilities
Published Oct 26, 2023
·Updated
It was discovered that Exim incorrectly handled validation of user-supplied data, which could lead to memory corruption. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2023-42117) It was discovered that Exim incorrectly handled validation of user-supplied data, which could lead to an out-of-bounds read. An attacker could possibly use this issue to expose sensitive information. (CVE-2023-42119)
Affected Software
28 affected componentsFixes available
All of the following
ubuntu/exim4-daemon-heavy<4.96-17ubuntu2.1
4.96-17ubuntu2.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/exim4-daemon-light<4.96-17ubuntu2.1
4.96-17ubuntu2.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/exim4-daemon-heavy<4.96-14ubuntu1.3
4.96-14ubuntu1.3
Ubuntu Ubuntu=23.04
All of the following
ubuntu/exim4-daemon-light<4.96-14ubuntu1.3
4.96-14ubuntu1.3
Ubuntu Ubuntu=23.04
All of the following
ubuntu/exim4-daemon-heavy<4.95-4ubuntu2.4
4.95-4ubuntu2.4
Ubuntu Ubuntu=22.04
All of the following
ubuntu/exim4-daemon-light<4.95-4ubuntu2.4
4.95-4ubuntu2.4
Ubuntu Ubuntu=22.04
All of the following
ubuntu/exim4-daemon-heavy<4.93-13ubuntu1.9
4.93-13ubuntu1.9
Ubuntu Ubuntu=20.04
All of the following
ubuntu/exim4-daemon-light<4.93-13ubuntu1.9
4.93-13ubuntu1.9
Ubuntu Ubuntu=20.04
All of the following
ubuntu/exim4-daemon-heavy<4.90.1-1ubuntu1.10+esm2
4.90.1-1ubuntu1.10+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/exim4-daemon-light<4.90.1-1ubuntu1.10+esm2
4.90.1-1ubuntu1.10+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/exim4-daemon-heavy<4.86.2-2ubuntu2.6+esm5
4.86.2-2ubuntu2.6+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/exim4-daemon-light<4.86.2-2ubuntu2.6+esm5
4.86.2-2ubuntu2.6+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/exim4-daemon-heavy<4.82-3ubuntu2.4+esm7
4.82-3ubuntu2.4+esm7
Ubuntu Ubuntu=14.04
All of the following
ubuntu/exim4-daemon-light<4.82-3ubuntu2.4+esm7
4.82-3ubuntu2.4+esm7
Ubuntu Ubuntu=14.04
Event History
Oct 26, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this advisory?
CVE-2023-42117
2
What is the affected version of Exim?
4.96-17ubuntu2.1
3
Can the vulnerability lead to arbitrary code execution?
Yes, a remote attacker could possibly use this issue to execute arbitrary code.
4
What is the remediation for this vulnerability on Ubuntu 23.10?
Upgrade the exim4-daemon-heavy package to version 4.96-17ubuntu2.1.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the [Ubuntu Security Advisory](https://ubuntu.com/security/CVE-2023-42117).