Bug 1142207 - (CVE-2019-13917) VUL-0: CVE-2019-13917: exim: OVE-20190718-0006
(CVE-2019-13917)
VUL-0: CVE-2019-13917: exim: OVE-20190718-0006
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.0
Other Other
: P3 - Medium : Major (vote)
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-07-19 13:42 UTC by Marcus Meissner
Modified: 2021-05-20 13:24 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 2 Alexandros Toptsoglou 2019-07-25 13:51:32 UTC
CVE ID:     CVE-2019-13917
OVE ID:     OVE-20190718-0006
Date:       2019-07-18
Credits:    Jeremy Harris
Version(s): 4.85 up to and including 4.92
Issue:      A local or remote attacker can execute programs with root
            privileges - if you've an unusual configuration. For details
	    see below.

Coordinated Release Date (CRD) for Exim 4.92.1:
            Thu Jul 25 10:00:00 UTC 2019

Contact:    exim-security@exim.org

We released Exim 4.92.1. This is a security update based on 4.92.

Conditions to be vulnerable
===========================

If your configuration uses the ${sort } expansion for items that can be
controlled by an attacker (e.g. $local_part, $domain). The default
config, as shipped by the Exim developers, does not contain ${sort }.

Details
=======

The vulnerability is exploitable either remotely or locally and could
be used to execute other programs with root privilege.  The ${sort }
expansion re-evaluates its items.

Mitigation
==========

Do not use ${sort } in your configuration.

Fix
===

Install a fixed package supplied by your distribution.
or download and build a fixed version:

For release tarballs (exim-4.92.1):

    http://ftp.exim.org/pub/exim/exim4/

The package files are signed with a key from the developers
key set: https://ftp.exim.org/pub/exim/Exim-Maintainers-Keyring.asc

For the full Git repo:

    https://git.exim.org/exim.git
    https://github.com/Exim/exim    [mirror of the above]
    - tag    exim-4.92.1
    - branch exim-4.92.1+fixes

The tagged commit is the officially released version. The tag is signed
with a key from the developers keyset.  The +fixes branch isn't
officially maintained, but contains the security fix *and* useful
patches.  The relevant commit is signed with a key from the developers
keyset. The old exim-4.92+fixes branch is being functionally replaced by
the new exim-4.92.1+fixes branch.

If you can't install the above versions, ask your package maintainer for
a version containing the backported fix. On request and depending on our
resources we will support you in backporting the fix.  (Please note,
that Exim project officially doesn't support versions prior the current
stable version.)

Timeline
========

t0: Thu Jul 18 2019
    - this notice to distros@vs.openwall.org and exim-maintainers@exim.org
    - open limited access to our security Git repo. See below.

t0+~4d: Mon Jul 22 10:00:00 UTC 2019 [NOW]
    - heads-up notice to oss-security@lists.openwall.com,
      exim-users@exim.org, and exim-announce@exim.org

t0+~7d: Thu Jul 25 10:00:00 UTC 2019 [NOW]
    - Coordinated relase date
    - publish the patches in our official and public Git repositories
      and the packages on our FTP server.
Comment 3 Swamp Workflow Management 2019-07-26 11:10:06 UTC
This is an autogenerated message for OBS integration:
This bug (1142207) was mentioned in
https://build.opensuse.org/request/show/718816 15.1 / exim
https://build.opensuse.org/request/show/718817 15.0 / exim
Comment 4 Alexandros Toptsoglou 2019-12-09 10:01:25 UTC
Released
Comment 5 OBSbugzilla Bot 2021-05-06 16:50:07 UTC
This is an autogenerated message for OBS integration:
This bug (1142207) was mentioned in
https://build.opensuse.org/request/show/891098 Backports:SLE-15-SP1 / exim
Comment 6 Swamp Workflow Management 2021-05-20 13:24:54 UTC
openSUSE-SU-2021:0753-1: An update that fixes 30 vulnerabilities is now available.

Category: security (critical)
Bug References: 1079832,1136587,1142207,1154183,1160726,1171490,1171877,1173693,1185631
CVE References: CVE-2017-1000369,CVE-2017-16943,CVE-2017-16944,CVE-2018-6789,CVE-2019-10149,CVE-2019-13917,CVE-2019-15846,CVE-2019-16928,CVE-2020-12783,CVE-2020-28007,CVE-2020-28008,CVE-2020-28009,CVE-2020-28010,CVE-2020-28011,CVE-2020-28012,CVE-2020-28013,CVE-2020-28014,CVE-2020-28015,CVE-2020-28016,CVE-2020-28017,CVE-2020-28018,CVE-2020-28019,CVE-2020-28020,CVE-2020-28021,CVE-2020-28022,CVE-2020-28023,CVE-2020-28024,CVE-2020-28025,CVE-2020-28026,CVE-2020-8015
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP1 (src):    exim-4.94.2-bp151.2.4.1, libspf2-1.2.10-bp151.4.1