EximÔ¶³Ì¶ÑÒç¶Âí½Å°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-01

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-16928£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Exim 4.92¡¢Exim 4.92.1¡¢Exim4.92.2


·ì϶¸ÅÊö


EximÊÇÒ»¸öÔËÐÐÓÚUnixϵͳÖеĿªÔ´ÐÂÎÅ´«ËÍ´úÀí£¨MTA£©£¬ËüÖØÒªÕÆ¹ÜÓʼþµÄ·ÓÉ¡¢×ª·¢ºÍͶµÝ¡£


EximÔ´´úÂëstring.cÎļþÖеÄstring_vformatº¯Êý´æÔÚÒ»´¦¶ÑÒç¶Âí½Å£¬¹¥»÷ÕßÄܹ»Í¨¹ýSMTPºÍ̸ÖеÄEHLO³¤×Ö·ûÀ´µ¼ÖÂEximµÄÒì³£´¥·¢¡£


·ì϶´¥·¢Ô´ÂëÈçÏÂËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



·ì϶ÑéÖ¤


POC: https://git.exim.org/exim.git/patch/478effbfd9c3cc5a627fc671d4bf94d13670d65f¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Exim 4.92.3ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://exim.org¡£


²Î¿¼Á´½Ó


https://git.exim.org/exim.git/patch/478effbfd9c3cc5a627fc671d4bf94d13670d65f