Three critical security vulnerabilities have been discovered in the widely-used Exim open-source email transfer agent, including a NTLM challenge out-of-bounds read information disclosure bug ( CVE-2023-42114 ), a AUTH out-of-bounds write remote code execution (RCE) vulnerability ( CVE-2023-42115 ), and a SMTP challenge stack-based buffer overflow RCE flaw ( CVE-2023-42116 ). . These issues could result in malware execution, system compromise, and information disclosure on impacted systems. An essential update for Exim has been released to fix these critical issues. We strongly recommend that all affected users apply the updates released by Debian , Debian LTS , openSUSE , and Ubuntu now to protect their critical systems and sensitive data against attacks leading to compromise. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Essential patches for Exim address RCE and information leak vulnerabilities, safeguarding systems from malicious code execution and potential breaches.. Exim Security Updates, Remote Code Execution, Information Disclosure, Open Source Email Vulnerabilities. . Brittany Day
A set of dangerous vulnerabilities have been discovered in the Exim mail server. Remote code execution, privilege escalation to root and lateral movement through a victim’s environment are all on offer for the unpatched or unaware. . A veritable cornucopia of security vulnerabilities in the Exim mail server have been uncovered, some of which could be chained together for unauthenticated remote code execution (RCE), gaining root privileges and worm-style lateral movement, according to researchers. The Qualys Research Team has discovered a whopping 21 bugs in the popular mail transfer agent (MTA), which was built to send and receive email on major Unix-like operating systems. It comes pre-installed on Linux distributions such as Debian, for instance. The link for this article located at ThreatPost is no longer available. . A collection of critical weaknesses in the Exim email server may result in remote code execution and unauthorized privilege escalation threats.. Exim Mail Server, Remote Exploit, Security Flaws. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.