Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-42114
HistorySep 28, 2023 - 12:00 a.m.

CVE-2023-42114

2023-09-2800:00:00
ubuntu.com
ubuntu.com
6
exim
ntlm
out-of-bounds
information disclosure
vulnerability
validation
zdi-can-17433
remote attackers
sensitive information
authentication
data structure

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.0%

Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure
Vulnerability. This vulnerability allows remote attackers to disclose
sensitive information on affected installations of Exim. Authentication is
not required to exploit this vulnerability. The specific flaw exists within
the handling of NTLM challenge requests. The issue results from the lack of
proper validation of user-supplied data, which can result in a read past
the end of an allocated data structure. An attacker can leverage this
vulnerability to disclose information in the context of the service
account. Was ZDI-CAN-17433.

Notes

Author Note
eslerm no security patches available, see ZDI’s timeline
allenpthuang patches now available, see the thread on Openwall
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchexim4< 4.90.1-1ubuntu1.10+esm1UNKNOWN
ubuntu20.04noarchexim4< 4.93-13ubuntu1.8UNKNOWN
ubuntu22.04noarchexim4< 4.95-4ubuntu2.3UNKNOWN
ubuntu23.04noarchexim4< 4.96-14ubuntu1.2UNKNOWN
ubuntu23.10noarchexim4< 4.96-17ubuntu2UNKNOWN
ubuntu14.04noarchexim4< 4.82-3ubuntu2.4+esm6UNKNOWN
ubuntu16.04noarchexim4< 4.86.2-2ubuntu2.6+esm4UNKNOWN

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.0%