Exim – remote attacker can execute programs with root privileges
lists.exim.org
lists.exim.org
Exim is a mail transfer agent (MTA) used on Unix-like operating systems. [...] In August 2019 [...] approximately 57% of the publicly reachable mail-servers on the Internet ran Exim.
Yikes.
edit: This might be a better summary of the vulnerability: https://www.tenable.com/blog/cve-2019-15846-unauthenticated-...
https://www.tenable.com/blog/cve-2019-15846-unauthenticated-...
Granted, there will still be the possibility of remote code execution as a non-root user, but at least you're not handing an attacker root privileges by default.
I guess this is why Ubuntu ships exim binary with setuid bit on it
Maybe the Exim people don't feel like its worthwhile to rearchitect it, given that there are MTA's with more secure designs/implementations out there already.
SMTP daemon itself does not run as root (on default Debian it runs as "Debian-exim" user). Some processes do need to run as root for local delivery, as others have mentioned.
How exactly this exploit works around that I don't know. PoC isn't public. Bugs happen, even with secure designs.
https://www.openwall.com/lists/oss-security/2019/09/07/2
That implies it is the processing from the spool that is at fault; something is serialized and later read back.
* https://www.exim.org/exim-html-3.20/doc/html/spec_55.html
Like any MTA it needs to be root to connect to port 25. It can and does drop privilege after that. Like any MTA it needs to have a process running as root to do local deliveries as a particular user and to do .forwards . It appears that process is what is being attacked here. If you don't do local deliveries/.forwards, you don't have to have any processes running as root.
Exim itself dates from 1995[3].
I'm not really up to date on the use of capabilities, but it would seem that it can be setup before running the main processes anyway[4] using the setcap command (not sure how portable this is on other platforms, eg. BSD's) and it would appear to be a distribution/packaging issue in that context anyway.
There is also always the possibility of setting the port used for SMTP connections to a port higher than 1024 anyway, and using iptables/firewalld etc. to forward port 25 to that unprivileged port, as also discussed in [4].
Of course, neither of these options help in the specific case of needing to access user's home directories, either to read .forward files or deliver mail there directly.
[1] https://stackoverflow.com/questions/413807/is-there-a-way-fo...
[2] https://lwn.net/Articles/266521/
[3] https://en.wikipedia.org/wiki/Exim#Origin
[4] https://security.stackexchange.com/questions/71922/postfix-m...
The actual commit for this vuln is here: https://github.com/Exim/exim/commit/2600301ba6dbac5c9d640c87...
*(++p) --- what did you think it would do without the parentheses...?
isdigit(ch) && ch != '8' && ch != '9' --- why not the simpler ch >= '0' && ch <= '7' ?
That code reminds me of FizzBuzz and the huge gap in competence it demonstrates, i.e. a surprisingly large number of "programmers" fail to write correct solutions to the simplest of problems. Perhaps "unescape a string" needs to be an interview question with as much attention as FizzBuzz, both because it has a practical application and can show a lot about someone's skill. Admittedly, I may be biased because I have done a lot of parsing and other compiler-ish work, but parsing text is really not an uncommon thing to do in a lot of applications.https://www.cvedetails.com/vendor/10919/Exim.html 12 RCE CVE entries since the CVE system started.
It also can do things that other MTAs can't do at all, again due to it being a monolith.
Postfix for example is made out of a string of independent programs that pass mail to one another. Once a program has an email that program can only deal with the email itself or pass it along to the next program. That limits what can be done with that email and makes the configuration harder to understand.
(I don't send e-mail to the outside or listen for any outside e-mail, so the choice of MTA is irrelevant to me as long as the system can still send over localhost to /var/mail/$USER.)
Interestingly, other panels seem to use other SMTP servers: https://www.liquidweb.com/kb/comparison-of-the-four-major-se...
Disclaimer: just reading about opensmtp, I'm using postfix
Exim is an SMTP server (MTA), not an email client (MUA).
It has "enterprise" in the name though so it's unlikely to be very robust or secure.
Otherwise, business opportunity for other language communities.
Thunderbird is an MUA and is not a substitute for an MTA like Exim.
Flexibility, mostly. It's configuration file includes a programming language of sorts, which means most things can be done write resorting to plugins or worse - having to write one.
https://lists.exim.org/lurker/message/20181228.202226.22d1c4...
I just tested version 4.92, which is still affected, and it doesn't seem like there is any interest in fixing this vulnerability.
> Add - as part of the mail ACL (the ACL referenced by the main config option "acl_smtp_mail"):
deny condition = ${if eq{\\}{${substr{-1}{1}{$tls_in_sni}}}}
deny condition = ${if eq{\\}{${substr{-1}{1}{$tls_in_peerdn}}}}I can’t find this file in the Git repository. Does anyone know where it is?
No kidding? Turning off TLS isn't an option at many installations. It's gotta work.
I just don't trust data to be secure AND persistent.
Would any of the people downvoting me stake their life on keeping a short string of characters secure on a connected computer forever?