CVE-2017-1000369

NameCVE-2017-1000369
DescriptionExim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note that at this time upstream has released a patch (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21), but it is not known if a new point release is available that addresses this issue at this time.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1001-1, DSA-3888-1
NVD severitylow (attack range: local)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
exim4 (PTS)wheezy4.80-7+deb7u3vulnerable
wheezy (security)4.80-7+deb7u5fixed
jessie (security), jessie4.84.2-2+deb8u4fixed
stretch (security), stretch4.89-2+deb9u1fixed
buster, sid4.89-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
exim4source(unstable)4.89-3low
exim4sourcejessie4.84.2-2+deb8u4lowDSA-3888-1
exim4sourcestretch4.89-2+deb9u1lowDSA-3888-1
exim4sourcewheezy4.80-7+deb7u5lowDLA-1001-1

Notes

https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt

Search for package or bug name: Reporting problems