Exim libspf2 Integer Underflow Remote Code Execution Vulnerability
CVE-2023-42118
7.5HIGH
What is CVE-2023-42118?
An integer underflow vulnerability in Exim's libspf2 component allows attackers to execute arbitrary code through a remote exploit. The flaw occurs during the parsing of SPF macros, where user-supplied data is not adequately validated. This oversight can lead to an integer underflow prior to memory writing, enabling attackers to leverage this vulnerability without authentication and execute arbitrary code within the context of the service account. Such vulnerabilities pose significant risks to email security and the integrity of the affected systems.
Affected Version(s)
libspf2 exim 4.96-RC0-14-24b8ed847-XX
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved