Bug 869953 (CVE-2012-5671)
Summary: | CVE-2012-5671 exim: Heap-buffer overflow in DNS decode logic used for DKIM | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Huzaifa S. Sidhpurwala <huzaifas> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | urgent | Docs Contact: | |||||
Priority: | urgent | ||||||
Version: | unspecified | CC: | customercare, jlieskov, jrusnack, jskarvad, rcvalle, security-response-team | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | exim 4.80.1 | Doc Type: | Bug Fix | ||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2013-02-25 15:27:40 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 870347, 870348 | ||||||
Bug Blocks: | 869954 | ||||||
Attachments: |
|
Description
Huzaifa S. Sidhpurwala
2012-10-25 08:25:23 UTC
Created attachment 633222 [details]
dkim-dns-buffer-overflow-protection-patch
Support for DKIM (DomainKeys Identified Mail) in exim was introduced in version 4.70. Also version 4.69 had experimental support. More details available at: http://wiki.exim.org/DKIM Red Hat Enterprise Linux 5, ships version exim-4.63, which does not contain the vulnerable DKIM code. Hence the version of exim shipped with Red Hat Enterprise Linux 5 is not vulnerable to this issue. Statement: Not Vulnerable. This issue does not affect the version of exim as shipped with Red Hat Enterprise Linux 5. This issue affects the version of exim as shipped with Fedora 16 and Fedora 17. The issue affects the version of exim as shipped with EPEL-6. Created exim tracking bugs for this issue Affects: fedora-all [bug 870347] Affects: epel-6 [bug 870348] *** Bug 870356 has been marked as a duplicate of this bug. *** Can this be closed? It was fixed for FC 16 / 17 and FC 18 comes with 4.80.1 Yes, closing, thank you! |