CVE Vulnerabilities

CVE-2023-42118

Integer Underflow (Wrap or Wraparound)

Published: May 03, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the parsing of SPF macros. When parsing SPF macros, the process does not properly validate user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17578.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
Exim4 Ubuntu bionic *
Exim4 Ubuntu lunar *
Exim4 Ubuntu mantic *
Exim4 Ubuntu trusty *
Exim4 Ubuntu trusty/esm *
Exim4 Ubuntu xenial *
Libspf2 Ubuntu bionic *
Libspf2 Ubuntu lunar *
Libspf2 Ubuntu mantic *
Libspf2 Ubuntu trusty *
Libspf2 Ubuntu xenial *

References