Bug 1517566 - Exim: remote code execution if chunking is enabled (CVE-2017-16943)
Summary: Exim: remote code execution if chunking is enabled (CVE-2017-16943)
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: exim
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Jaroslav Škarvada
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-11-26 21:33 UTC by Felix Schwarz
Modified: 2017-12-27 21:33 UTC (History)
4 users (show)

Fixed In Version: exim-4.89-7.fc27 exim-4.89-7.fc26 exim-4.89-4.el7 exim-4.89-4.el6
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-12-12 11:21:43 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Felix Schwarz 2017-11-26 21:33:46 UTC
All Exim versions since 4.88 are vulnerable to a remote code execution attack if chunking is enabled (CVE-2017-16944).

Bug fix is already committed to git:
https://bugs.exim.org/show_bug.cgi?id=2199

More information:
http://seclists.org/oss-sec/2017/q4/325


Furthermore there is another DoS (CVE-2017-16944): https://bugs.exim.org/show_bug.cgi?id=2201

Comment 1 Fedora Update System 2017-11-27 14:32:53 UTC
exim-4.89-6.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2017-ff25180888

Comment 2 Fedora Update System 2017-11-27 14:41:49 UTC
exim-4.89-3.el6 has been submitted as an update to Fedora EPEL 6. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-977c974584

Comment 3 Fedora Update System 2017-11-27 14:42:43 UTC
exim-4.89-6.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-ef2108bde5

Comment 4 Fedora Update System 2017-11-28 06:46:11 UTC
exim-4.89-6.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-ff25180888

Comment 5 Fedora Update System 2017-11-28 07:24:48 UTC
exim-4.89-6.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-ef2108bde5

Comment 6 Fedora Update System 2017-11-29 00:15:30 UTC
exim-4.89-3.el6 has been pushed to the Fedora EPEL 6 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-977c974584

Comment 7 Fedora Update System 2017-11-29 02:06:37 UTC
exim-4.89-3.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-aa566558a0

Comment 8 Fedora Update System 2017-12-01 13:14:32 UTC
exim-4.89-7.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2017-0053bb9719

Comment 9 Fedora Update System 2017-12-01 13:18:23 UTC
exim-4.89-7.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-0032baa7d7

Comment 10 Fedora Update System 2017-12-01 15:09:20 UTC
exim-4.89-4.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-f58e92e860

Comment 11 Fedora Update System 2017-12-01 15:10:10 UTC
exim-4.89-4.el6 has been submitted as an update to Fedora EPEL 6. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-678916467d

Comment 12 Fedora Update System 2017-12-02 08:31:47 UTC
exim-4.89-4.el6 has been pushed to the Fedora EPEL 6 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-678916467d

Comment 13 Fedora Update System 2017-12-02 19:55:14 UTC
exim-4.89-7.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-0053bb9719

Comment 14 Fedora Update System 2017-12-02 21:47:49 UTC
exim-4.89-4.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-f58e92e860

Comment 15 Fedora Update System 2017-12-02 22:39:45 UTC
exim-4.89-7.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-0032baa7d7

Comment 16 Fedora Update System 2017-12-12 11:21:43 UTC
exim-4.89-7.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.

Comment 17 Fedora Update System 2017-12-12 13:42:56 UTC
exim-4.89-7.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.

Comment 18 Fedora Update System 2017-12-19 19:13:00 UTC
exim-4.89-4.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.

Comment 19 Fedora Update System 2017-12-27 21:33:51 UTC
exim-4.89-4.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.