Exim libspf2 Integer Underflow Remote Code Execution Vulnerability
CVE-2023-42118

7.5HIGH

Key Information:

Vendor

Exim

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-42118?

An integer underflow vulnerability in Exim's libspf2 component allows attackers to execute arbitrary code through a remote exploit. The flaw occurs during the parsing of SPF macros, where user-supplied data is not adequately validated. This oversight can lead to an integer underflow prior to memory writing, enabling attackers to leverage this vulnerability without authentication and execute arbitrary code within the context of the service account. Such vulnerabilities pose significant risks to email security and the integrity of the affected systems.

Affected Version(s)

libspf2 exim 4.96-RC0-14-24b8ed847-XX

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.