ALAS-2023-1860

Related Vulnerabilities: CVE-2023-42116   CVE-2023-42117  

Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1470/ (CVE-2023-42116) Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1471/ (CVE-2023-42117)

ALAS-2023-1860


Amazon Linux 1 Security Advisory: ALAS-2023-1860
Advisory Release Date: 2023-10-12 15:48 Pacific
Advisory Updated Date: 2023-10-24 21:38 Pacific
Severity: Important

Issue Overview:

Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability

NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1470/ (CVE-2023-42116)

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability

NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1471/ (CVE-2023-42117)


Affected Packages:

exim


Issue Correction:
Run yum update exim to update your system.

New Packages:
i686:
    exim-pgsql-4.92-1.39.amzn1.i686
    exim-debuginfo-4.92-1.39.amzn1.i686
    exim-mon-4.92-1.39.amzn1.i686
    exim-mysql-4.92-1.39.amzn1.i686
    exim-greylist-4.92-1.39.amzn1.i686
    exim-4.92-1.39.amzn1.i686

src:
    exim-4.92-1.39.amzn1.src

x86_64:
    exim-4.92-1.39.amzn1.x86_64
    exim-mon-4.92-1.39.amzn1.x86_64
    exim-mysql-4.92-1.39.amzn1.x86_64
    exim-pgsql-4.92-1.39.amzn1.x86_64
    exim-debuginfo-4.92-1.39.amzn1.x86_64
    exim-greylist-4.92-1.39.amzn1.x86_64