Oval Definition:oval:com.redhat.rhsa:def:20050025
Revision Date:2005-02-15Version:502
Title:RHSA-2005:025: exim security update (Moderate)
Description:Exim is a mail transport agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet.

A buffer overflow was discovered in the spa_base64_to_bits function in Exim, as originally obtained from Samba code. If SPA authentication is enabled, a remote attacker may be able to exploit this vulnerability to execute arbitrary code as the 'exim' user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0022 to this issue. Please note that SPA authentication is not enabled by default in Red Hat Enterprise Linux 4.

Buffer overflow flaws were discovered in the host_aton and dns_build_reverse functions in Exim. A local user can trigger these flaws by executing exim with carefully crafted command line arguments and may be able to gain the privileges of the 'exim' account. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0021 to this issue.

Users of Exim are advised to update to these erratum packages which contain backported patches to correct these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-0021
CVE-2005-0022
RHSA-2005:025-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND Package Information
  • exim-mon is earlier than 0:4.43-1.RHEL4.3
  • AND exim-mon is signed with Red Hat master key
  • OR
  • exim-doc is earlier than 0:4.43-1.RHEL4.3
  • AND exim-doc is signed with Red Hat master key
  • OR
  • exim is earlier than 0:4.43-1.RHEL4.3
  • AND exim is signed with Red Hat master key
  • OR
  • exim-sa is earlier than 0:4.43-1.RHEL4.3
  • AND exim-sa is signed with Red Hat master key
  • BACK