Bug 2241538 (CVE-2023-42114)

Summary: CVE-2023-42114 Exim: NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability
Product: [Other] Security Response Reporter: Nick Tait <ntait>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: customercare, fschwarz, upstream-release-monitoring
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
An out-of-bounds read vulnerability was found in Exim within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to disclose information in the context of the service account. Authentication is not required to exploit this vulnerability.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2241539, 2241540    
Bug Blocks: 2241518    

Comment 1 Nick Tait 2023-09-30 18:01:10 UTC
Created exim tracking bugs for this issue:

Affects: epel-all [bug 2241540]
Affects: fedora-all [bug 2241539]

Comment 2 Jaroslav Škarvada 2023-10-02 12:38:14 UTC
*** Bug 2241735 has been marked as a duplicate of this bug. ***

Comment 3 Jaroslav Škarvada 2023-10-02 12:39:39 UTC
*** Bug 2241470 has been marked as a duplicate of this bug. ***

Comment 4 Jaroslav Škarvada 2023-10-02 12:40:03 UTC
*** Bug 2241455 has been marked as a duplicate of this bug. ***

Comment 5 customercare 2024-01-12 14:30:42 UTC
can we close this bug?