iTnews Asia
  • Home
  • News
  • Security

Exim mail servers worldwide need urgent patches

Exim mail servers worldwide need urgent patches

Three out of six issues already fixed.

By Richard Chirgwin on Oct 4, 2023 10:33AM

Bugs in the popular Exim message transfer agent (MTA) software have exposed hundreds of thousands of systems to remote code execution (RCE).

Since its role is handling email, Exim runs exposed to the internet, meaning that any vulnerability is likely to be exploited.

According to a regular Securityspace survey, there were more than 300,000 Exim servers visible from the internet on October 1.

CVE-2023-42115 is a bug in Exim's simple mail transfer protocol (SMTP) service, which listens to TCP port 25. 

The bug allows the attacker to write data past the end of a buffer, and an exploit gives an unauthenticated remote attacker the ability to run code in the context of the SMTP service, giving it a critical-rated CVSS score of 9.8.

The bug was released through the Zero Day Initiative, as one of six zero-day vulnerabilities reported through the scheme.

There were also two high-rated bugs (CVSS score 8.1): CVE-2023-42116, a buffer overflow in its SMTP challenge component; and CVE-2023-42117, a memory corruption bug in the SMTP service that could also give an attacker RCE.

According to this post to the oss-sec mailing list, patches have been made available for three of the bugs and will soon be applied by Exim's maintainers, with Heiko Schlittermann saying the maintainers need more information about the remaining issues. 

Exim needed urgent patches twice in 2019 – in June and October – and in 2020, America’s National Security Agency warned the MTA was being targeted by Russian hacking operation Sandworm.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
exim sandworm security software

Related Articles

  • Proofpoint CEO: A tool-based approach for cybersecurity is impractical
  • Akamai: AI-security is both a security imperative and an economic necessity
  • The real-life Tom & Jerry chase
  • How can we bolster our resilience against AI-enabled e-mail attacks?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

Akamai: AI-security is both a security imperative and an economic necessity

Akamai: AI-security is both a security imperative and an economic necessity

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.