Bugzilla – Bug 1202205
VUL-0: CVE-2022-37452: exim: heap overflow
Last modified: 2023-10-04 06:31:20 UTC
CVE-2022-37452 Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-37452 https://www.openwall.com/lists/oss-security/2022/08/06/8 https://github.com/ivd38/exim_overflow https://github.com/Exim/exim/commit/d4bc023436e4cce7c23c5f8bb5199e178b4cc743 https://github.com/Exim/exim/compare/exim-4.94...exim-4.95 https://github.com/Exim/exim/wiki/EximSecurity http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37452 https://www.exim.org/static/doc/security/
same as the other bug: already fixed in Factory, still open for openSUSE:Backports:*:Update
This is an autogenerated message for OBS integration: This bug (1202205) was mentioned in https://build.opensuse.org/request/show/993692 Backports:SLE-12-SP4+Backports:SLE-15-SP3+Backports:SLE-15-SP4 / exim
fixed via update https://build.opensuse.org/request/show/993692