Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Ubuntu Local Security Checks --> Category: infos

USN56-1 : exim4 vulnerabilities Vulnerability Scan


Vulnerability Scan Summary
exim4 vulnerabilities

Detailed Explanation for this Vulnerability Test

Synopsis :

These remote packages are missing security patches :
- exim4
- exim4-base
- exim4-config
- exim4-daemon-heavy
- exim4-daemon-light
- eximon4


Description :

A flaw has been found in the host_aton() function, which can overflow
a buffer if it is presented with an illegal IPv6 address that has more
than 8 components. When supplying certain command line parameters, the
input was not checked, so that a local attacker could possibly exploit
the buffer overflow to run arbitrary code with the rights of the
Exim mail server. (CVE-2005-0021)

Additionally, the BASE64 decoder in the SPA authentication handler did
not check the size of its output buffer. By sending an invalid BASE64
authentication string, a remote attacker could overflow the buffer,
which could possibly be exploited to run arbitrary code with the
rights of the Exim mail server. (CVE-2005-0022)

Solution :

Upgrade to :
- exim4-4.34-5ubuntu1.1 (Ubuntu 4.10)
- exim4-base-4.34-5ubuntu1.1 (Ubuntu 4.10)
- exim4-config-4.34-5ubuntu1.1 (Ubuntu 4.10)
- exim4-daemon-heavy-4.34-5ubuntu1.1 (Ubuntu 4.10)
- exim4-daemon-light-4.34-5ubuntu1.1 (Ubuntu 4.10)
- eximon4-4.34-5ubuntu1.1 (Ubuntu 4.10)



Threat Level: High


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.