TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

CVE-2023-42115 Exim RCE

7 pointsby kroover 1 year ago

2 comments

pjaover 1 year ago
One of these requires having the spa challenge authentication method active, which concerns NTLM passwords. I’m going to guess that approximately zero currently running exim mailservers are using this authentication method. It’s not even mentioned in the default Debian configuration files.<p>Another is a stack overflow, which will hopefully be caught be the stack-protector hardening on Debian&#x2F;Ubuntu.<p>Which leaves the worst of them - the buffer overflow :(
kroover 1 year ago
The site makes it appear Exim never took action on their info to them more than a year ago.<p>other: <a href="https:&#x2F;&#x2F;security-tracker.debian.org&#x2F;tracker&#x2F;CVE-2023-42115" rel="nofollow noreferrer">https:&#x2F;&#x2F;security-tracker.debian.org&#x2F;tracker&#x2F;CVE-2023-42115</a>
评论 #37711721 未加载