Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2023-42119

3.1LOW

Key Information:

Vendor

Exim

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-42119?

The Exim SMTP Server is susceptible to an out-of-bounds read vulnerability that occurs due to inadequate validation of user-supplied data. This issue resides within the SMTP service that typically operates on TCP port 25. Attackers with network access can exploit this flaw to disclose sensitive information from the affected Exim installations without requiring authentication. By exploiting this vulnerability, an attacker could potentially leverage additional vulnerabilities to execute arbitrary code in the context of the service account, thus posing a significant security risk to the integrity of the system.

Affected Version(s)

Exim exim 4.96-RC0-14-24b8ed847-XX

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-42119 : Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability