![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.53192 |
Category: | Debian Local Security Checks |
Title: | Debian Security Advisory DSA 502-1 (exim-tls) |
Summary: | The remote host is missing an update to exim-tls;announced via advisory DSA 502-1. |
Description: | Summary: The remote host is missing an update to exim-tls announced via advisory DSA 502-1. Vulnerability Insight: Georgi Guninski discovered two stack-based buffer overflows in exim and exim-tls. They can not be exploited with the default configuration from the Debian system, though. The Common Vulnerabilities and Exposures project identifies the following problems that are fixed with this update: CVE-2004-0399 When sender_verify = true is configured in exim.conf a buffer overflow can happen during verification of the sender. This problem is fixed in exim 4. CVE-2004-0400 When headers_check_syntax is configured in exim.conf a buffer overflow can happen during the header check. This problem does also exist in exim 4. For the stable distribution (woody) these problems have been fixed in version 3.35-3woody2. The unstable distribution (sid) does not contain exim-tls anymore. The functionality has been incorporated in the main exim versions which have these problems fixed in version 3.36-11 for exim 3 and in version 4.33-1 for exim 4. Solution: We recommend that you upgrade your exim-tls package. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2004-0399 Debian Security Information: DSA-501 (Google Search) http://www.debian.org/security/2004/dsa-501 Debian Security Information: DSA-502 (Google Search) http://www.debian.org/security/2004/dsa-502 http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html http://www.guninski.com/exim1.html http://secunia.com/advisories/11558 XForce ISS Database: exim-requireverify-bo(16079) https://exchange.xforce.ibmcloud.com/vulnerabilities/16079 Common Vulnerability Exposure (CVE) ID: CVE-2004-0400 XForce ISS Database: exim-headerschecksyntax-bo(16077) https://exchange.xforce.ibmcloud.com/vulnerabilities/16077 |
Copyright | Copyright (C) 2008 E-Soft Inc. |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |