Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2023-42119
3.1LOW
What is CVE-2023-42119?
The Exim SMTP Server is susceptible to an out-of-bounds read vulnerability that occurs due to inadequate validation of user-supplied data. This issue resides within the SMTP service that typically operates on TCP port 25. Attackers with network access can exploit this flaw to disclose sensitive information from the affected Exim installations without requiring authentication. By exploiting this vulnerability, an attacker could potentially leverage additional vulnerabilities to execute arbitrary code in the context of the service account, thus posing a significant security risk to the integrity of the system.
Affected Version(s)
Exim exim 4.96-RC0-14-24b8ed847-XX
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
