Alerts This Week
Warning Icon 1 1,003
Alerts This Week
Warning Icon 1 1,003

Ubuntu 20.04/22.04 USN-5741-1 Moderate Exim Denial Of Service

ubuntu
Calendar Grey November 24, 2022
Dist Ubuntu Esm H88
Exim's vulnerabilities can cause system instability or unauthorized code execution on Ubuntu due to improper regular expression handling. Secure configuration guidance is provided
Exim could be made to crash or run programs if it processed specially crafted regular expressions.

Summary

Exim could be made to crash or run programs if it processed specially

crafted regular expressions.

Software Description:

- exim4: Exim is a mail transport agent

Details:

It was discovered that Exim incorrectly handled certain regular

expressions. An attacker could use this issue to cause Exim to crash,

resulting in a denial of service, or possibly execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
   exim4-base                      4.96-3ubuntu1.1
   exim4-daemon-heavy              4.96-3ubuntu1.1
   exim4-daemon-light              4.96-3ubuntu1.1

Ubuntu 22.04 LTS:
   exim4-base                      4.95-4ubuntu2.2
   exim4-daemon-heavy              4.95-4ubuntu2.2
   exim4-daemon-light              4.95-4ubuntu2.2

Ubuntu 20.04 LTS:
   exim4-base                      4.93-13ubuntu1.7
   exim4-daemon-heavy              4.93-13ubuntu1.7
   exim4-daemon-light              4.93-13ubuntu1.7

Ubuntu 18.04 LTS:
   exim4-base                      4.90.1-1ubuntu1.10
   exim4-daemon-heavy              4.90.1-1ubuntu1.10
   exim4-daemon-light              4.90.1-1ubuntu1.10

In general, a standard system update will make all the necessary changes.

References

CVE-2022-3559

November 24, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here