Bug 1171490 (CVE-2020-12783) - VUL-0: CVE-2020-12783: exim: out-of-bounds read in the SPA authenticator which could lead to SPA/NTLM authentication bypass
Summary: VUL-0: CVE-2020-12783: exim: out-of-bounds read in the SPA authenticator whic...
Status: RESOLVED FIXED
Alias: CVE-2020-12783
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.1
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: Leap 15.1
Assignee: Peter Wullinger
QA Contact: E-mail List
URL: https://smash.suse.de/issue/259415/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-05-12 07:36 UTC by Alexandros Toptsoglou
Modified: 2024-07-15 17:05 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Peter Wullinger 2020-05-12 08:40:44 UTC
(In reply to Alexandros Toptsoglou from comment #0)
> CVE-2020-12783
> 
> Exim through 4.93 has an out-of-bounds read in the SPA authenticator that
> could
> result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
> 

Thank you. New server:mail package now has the relevant fix(es) from 4.93+fixes.
Comment 2 Peter Wullinger 2020-05-25 05:32:53 UTC
fixed in server:mail and Factory as of Tue May 12.
Comment 3 OBSbugzilla Bot 2021-05-06 16:50:11 UTC
This is an autogenerated message for OBS integration:
This bug (1171490) was mentioned in
https://build.opensuse.org/request/show/891096 15.2 / exim
https://build.opensuse.org/request/show/891098 Backports:SLE-15-SP1 / exim
Comment 4 Swamp Workflow Management 2021-05-07 13:15:33 UTC
openSUSE-SU-2021:0677-1: An update that fixes 26 vulnerabilities is now available.

Category: security (critical)
Bug References: 1079832,1171490,1171877,1173693,1185631
CVE References: CVE-2017-1000369,CVE-2017-16943,CVE-2017-16944,CVE-2018-6789,CVE-2019-16928,CVE-2020-12783,CVE-2020-28007,CVE-2020-28008,CVE-2020-28009,CVE-2020-28010,CVE-2020-28011,CVE-2020-28012,CVE-2020-28013,CVE-2020-28014,CVE-2020-28015,CVE-2020-28016,CVE-2020-28017,CVE-2020-28018,CVE-2020-28019,CVE-2020-28020,CVE-2020-28021,CVE-2020-28022,CVE-2020-28023,CVE-2020-28024,CVE-2020-28025,CVE-2020-28026
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    exim-4.94.2-lp152.8.3.1
Comment 5 Swamp Workflow Management 2021-05-20 13:17:21 UTC
openSUSE-SU-2021:0754-1: An update that fixes 26 vulnerabilities is now available.

Category: security (critical)
Bug References: 1079832,1171490,1171877,1173693,1185631
CVE References: CVE-2017-1000369,CVE-2017-16943,CVE-2017-16944,CVE-2018-6789,CVE-2019-16928,CVE-2020-12783,CVE-2020-28007,CVE-2020-28008,CVE-2020-28009,CVE-2020-28010,CVE-2020-28011,CVE-2020-28012,CVE-2020-28013,CVE-2020-28014,CVE-2020-28015,CVE-2020-28016,CVE-2020-28017,CVE-2020-28018,CVE-2020-28019,CVE-2020-28020,CVE-2020-28021,CVE-2020-28022,CVE-2020-28023,CVE-2020-28024,CVE-2020-28025,CVE-2020-28026
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP2 (src):    exim-4.94.2-bp152.6.4.1, libspf2-1.2.10-bp152.5.1
Comment 6 Swamp Workflow Management 2021-05-20 13:25:10 UTC
openSUSE-SU-2021:0753-1: An update that fixes 30 vulnerabilities is now available.

Category: security (critical)
Bug References: 1079832,1136587,1142207,1154183,1160726,1171490,1171877,1173693,1185631
CVE References: CVE-2017-1000369,CVE-2017-16943,CVE-2017-16944,CVE-2018-6789,CVE-2019-10149,CVE-2019-13917,CVE-2019-15846,CVE-2019-16928,CVE-2020-12783,CVE-2020-28007,CVE-2020-28008,CVE-2020-28009,CVE-2020-28010,CVE-2020-28011,CVE-2020-28012,CVE-2020-28013,CVE-2020-28014,CVE-2020-28015,CVE-2020-28016,CVE-2020-28017,CVE-2020-28018,CVE-2020-28019,CVE-2020-28020,CVE-2020-28021,CVE-2020-28022,CVE-2020-28023,CVE-2020-28024,CVE-2020-28025,CVE-2020-28026,CVE-2020-8015
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP1 (src):    exim-4.94.2-bp151.2.4.1, libspf2-1.2.10-bp151.4.1
Comment 7 OBSbugzilla Bot 2024-07-15 17:05:12 UTC
This is an autogenerated message for OBS integration:
This bug (1171490) was mentioned in
https://build.opensuse.org/request/show/1187597 Backports:SLE-15-SP6 / exim