PT-2022-6997 · Exim+5 · Exim+5

Published

2022-06-06

·

Updated

2025-08-07

·

CVE-2023-42114

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Exim (affected versions not specified)
Description The issue is related to the handling of NTLM challenge requests in Exim, which can result in a read past the end of an allocated data structure due to the lack of proper validation of user-supplied data. This allows remote attackers to disclose sensitive information on affected installations of Exim without requiring authentication. The specific flaw exists within the handling of NTLM challenge requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-7644
BDU:2023-06277
CVE-2023-42114
DLA-3599-1
DSA-5512-1
OPENSUSE-SU-2023:0293-1
OPENSUSE-SU-2024:0007-1
OPENSUSE-SU-2024:13282-1
USN-6411-1
ZDI-23-1468

Affected Products

Alt Linux
Astra Linux
Exim
Linuxmint
Red Os
Ubuntu