CVE-2014-2972
Description
expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
CVE-2014-2972 NameCVE-2014-2972 Descriptionexpand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed…
CVE-2014-2972
| Name | CVE-2014-2972 |
| Description | expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| exim4 (PTS) | bullseye | 4.94.2-7+deb11u3 | fixed |
| bullseye (security) | 4.94.2-7+deb11u5 | fixed | |
| bookworm | 4.96-15+deb12u9 | fixed | |
| bookworm (security) | 4.96-15+deb12u10 | fixed | |
| trixie | 4.98.2-1+deb13u2 | fixed | |
| trixie (security) | 4.98.2-1+deb13u3 | fixed | |
| forky, sid | 4.99.3-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| exim4 | source | wheezy | 4.80-7+deb7u1 | |||
| exim4 | source | (unstable) | 4.82.1-2 | low |
Notes
[squeeze] - exim4 <no-dsa> (Minor issue)
Apply commands
[squeeze] - exim4 <no-dsa> (Minor issue)
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 4.82.1-2 |
| debian | bullseye | fixed | 4.82.1-2 |
| debian | forky | fixed | 4.82.1-2 |
| debian | sid | fixed | 4.82.1-2 |
| debian | trixie | fixed | 4.82.1-2 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| exim | exim | {"endIncluding":"4.82.1"} | |
| exim | exim | 4.00 | |
| exim | exim | 4.01 | |
| exim | exim | 4.02 | |
| exim | exim | 4.03 | |
| exim | exim | 4.04 | |
| exim | exim | 4.05 | |
| exim | exim | 4.10 | |
| exim | exim | 4.11 | |
| exim | exim | 4.12 | |
| exim | exim | 4.14 | |
| exim | exim | 4.20 | |
| exim | exim | 4.21 | |
| exim | exim | 4.22 | |
| exim | exim | 4.23 | |
| exim | exim | 4.24 | |
| exim | exim | 4.30 | |
| exim | exim | 4.31 | |
| exim | exim | 4.32 | |
| exim | exim | 4.33 | |
| exim | exim | 4.34 | |
| exim | exim | 4.40 | |
| exim | exim | 4.41 | |
| exim | exim | 4.42 | |
| exim | exim | 4.43 | |
| exim | exim | 4.44 | |
| exim | exim | 4.50 | |
| exim | exim | 4.51 | |
| exim | exim | 4.52 | |
| exim | exim | 4.53 | |
| exim | exim | 4.54 | |
| exim | exim | 4.60 | |
| exim | exim | 4.61 | |
| exim | exim | 4.62 | |
| exim | exim | 4.63 | |
| exim | exim | 4.64 | |
| exim | exim | 4.65 | |
| exim | exim | 4.66 | |
| exim | exim | 4.67 | |
| exim | exim | 4.68 | |
| exim | exim | 4.69 | |
| exim | exim | 4.70 | |
| exim | exim | 4.71 | |
| exim | exim | 4.72 | |
| exim | exim | 4.73 | |
| exim | exim | 4.74 | |
| exim | exim | 4.75 | |
| exim | exim | 4.76 | |
| exim | exim | 4.77 | |
| exim | exim | 4.80 | |
| exim | exim | 4.80.1 | |
| exim | exim | 4.82 | |
References
- http://git.exim.org/exim.git/commitdiff/7685ce68148a083d7759e78d01aa5198fc099c44
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136251.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136264.html
- http://www.ubuntu.com/usn/USN-2933-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1122552
- https://lists.exim.org/lurker/message/20140722.145949.42c043f5.en.html
- https://lists.exim.org/lurker/message/20140722.152452.d6c019e8.en.html
- https://security.gentoo.org/glsa/201607-12
- https://security-tracker.debian.org/tracker/CVE-2014-2972
CWEs
CWE-189
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.