Bug 869953 - (CVE-2012-5671) CVE-2012-5671 exim: Heap-buffer overflow in DNS decode logic used for DKIM
CVE-2012-5671 exim: Heap-buffer overflow in DNS decode logic used for DKIM
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
urgent Severity urgent
: ---
: ---
Assigned To: Red Hat Product Security
impact=critical,public=20121026,repor...
: Security
Depends On: 870347 870348
Blocks: 869954
  Show dependency treegraph
 
Reported: 2012-10-25 04:25 EDT by Huzaifa S. Sidhpurwala
Modified: 2014-10-17 04:16 EDT (History)
6 users (show)

See Also:
Fixed In Version: exim 4.80.1
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-02-25 10:27:40 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)
dkim-dns-buffer-overflow-protection-patch (2.13 KB, patch)
2012-10-25 04:26 EDT, Huzaifa S. Sidhpurwala
no flags Details | Diff

  None (edit)
Description Huzaifa S. Sidhpurwala 2012-10-25 04:25:23 EDT
A heap-buffer overflow was found in the DKIM DNS decode logic, used by exim.  A remote attacker could use this flaw to execute arbitrary code on the mail server running Exim.

This is fixed in version 4.80.1
Comment 1 Huzaifa S. Sidhpurwala 2012-10-25 04:26:41 EDT
Created attachment 633222 [details]
dkim-dns-buffer-overflow-protection-patch
Comment 3 Huzaifa S. Sidhpurwala 2012-10-25 04:31:16 EDT
Support for DKIM (DomainKeys Identified Mail) in exim was introduced in version 4.70. Also version 4.69 had experimental support. More details available at:

http://wiki.exim.org/DKIM

Red Hat Enterprise Linux 5, ships version exim-4.63, which does not contain the vulnerable DKIM code. Hence the version of exim shipped with Red Hat Enterprise Linux 5 is not vulnerable to this issue.
Comment 4 Huzaifa S. Sidhpurwala 2012-10-25 04:32:12 EDT
Statement:

Not Vulnerable. This issue does not affect the version of exim as shipped with Red Hat Enterprise Linux 5.
Comment 5 Huzaifa S. Sidhpurwala 2012-10-25 04:34:18 EDT
This issue affects the version of exim as shipped with Fedora 16 and Fedora 17.

The issue affects the version of exim as shipped with EPEL-6.
Comment 6 Jan Lieskovsky 2012-10-26 04:31:38 EDT
Public via:
  https://lists.exim.org/lurker/message/20121026.080330.74b9147b.en.html
Comment 7 Jan Lieskovsky 2012-10-26 04:33:48 EDT
Created exim tracking bugs for this issue

Affects: fedora-all [bug 870347]
Affects: epel-6 [bug 870348]
Comment 8 Vincent Danen 2012-10-26 11:01:55 EDT
*** Bug 870356 has been marked as a duplicate of this bug. ***
Comment 9 customercare 2013-02-25 10:19:15 EST
Can this be closed? 

It was fixed for FC 16 / 17 and FC 18 comes with 4.80.1
Comment 10 Tomas Hoger 2013-02-25 10:27:40 EST
Yes, closing, thank you!

Note You need to log in before you can comment on or make changes to this bug.