LWN.net Logo

exim4: arbitrary code execution

Package(s):exim4 CVE #(s):CVE-2012-5671
Created:October 26, 2012 Updated:November 1, 2012
Description:

From the Debian advisory:

It was discovered that Exim, a mail transport agent, is not properly handling the decoding of DNS records for DKIM. Specifically, crafted records can yield to a heap-based buffer overflow. An attacker can exploit this flaw to execute arbitrary code.

Alerts:
Debian DSA-2566-1 2012-10-26
Ubuntu USN-1618-1 2012-10-26
openSUSE openSUSE-SU-2012:1404-1 2012-10-27
Fedora FEDORA-2012-17044 2012-10-30
Fedora FEDORA-2012-17085 2012-10-31

(Log in to post comments)

exim4: arbitrary code execution

Posted Nov 1, 2012 3:31 UTC (Thu) by Comet (subscriber, #11646) [Link]

4.80.1 release announcement, with details of how to work around:

https://lists.exim.org/lurker/message/20121026.080330.74b...

A couple more details, including the link to the Git commit where I fixed it:

http://www.exim.org/lurker/message/20121026.083548.464737...

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds