CVE-2022-3559
Published: 17 October 2022
A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.
Priority
Status
Package | Release | Status |
---|---|---|
exim4 Launchpad, Ubuntu, Debian |
bionic |
Released
(4.90.1-1ubuntu1.10)
|
focal |
Released
(4.93-13ubuntu1.7)
|
|
jammy |
Released
(4.95-4ubuntu2.2)
|
|
kinetic |
Released
(4.96-3ubuntu1.1)
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(4.96-4)
|
|
xenial |
Not vulnerable
(code not present)
|
|
Patches: upstream: https://git.exim.org/exim.git/commit/4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |