News: 1620235206

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

21 nails in Exim mail server: Vulnerabilities enable 'full remote unauthenticated code execution', millions of boxes at risk

(2021/05/05)


Researchers at security biz Qualys discovered 21 vulnerabilities in Exim, a popular mail server, which can be chained to obtain "a full remote unauthenticated code execution and gain root privileges on the Exim Server."

Exim is a mail transfer agent (MTA), responsible for receiving and forwarding email messages. It runs primarily on Unix or Linux and is the default MTA on Debian - though Ubuntu and Red Hat Enterprise Linux use Postfix by default.

Some hosting companies use Exim to provide email services to their customers, and it was also popular in universities and other educational institutions (it was initially developed at the University of Cambridge in 1995) though many of these have transitioned to Office 365 or Google email, not least [1]Cambridge itself .

[2]

[3]

[4]

According to one [5]recent survey nearly 60 per cent of mail servers visible on the internet use Exim, followed by Postfix at 34 per cent. Qualys said a Shodan search revealed nearly 4 million Exim servers exposed to the internet.

[6]

Qualys demonstrates a proof of concept exploit against the Exim mail server, achieving root access to the remote server

The Qualys researchers have now [7]reported on 21 critical vulnerabilities discovered via a code audit, 10 of which can be exploited remotely.

The local vulnerabilities are also an issue, as they can enable local users to escalate privileges to root. Most of the vulnerabilities are longstanding, the researchers say, with some going back to the beginning of its Git history (the Exim source code repository).

A proof of concept video shows an exploit (developed by Qualys but not publicly available) in action. "To run the exploit, all we need to do is point it to the target Exim server IP endpoint," explained researcher Bharat Jogi. The exploit starts with a use after free bug (where memory is referenced after it has been freed), then discovers where Exim's configuration resides in memory, and modifies it to "execute an arbitrary command."

This opens a Netcat shell, at which point the attacker has a local terminal as the Exim user. A further vulnerability allows the attacker to take ownership of any file on the system, because part of the Exim code runs as root. Ownership of the system password file then gives the user full root privileges.

Timing was tight

Qualys said it informed the Exim security team of some vulnerabilities on 20 October 2020, followed by a further list on 29 October. Exim maintainers gave Qualys access to its Git repository both to review and to assist with writing patches. The timing was tight, though: patches were not completed until 24th February, and the Exim team did not give access to packagers and maintainers, who are responsible for providing Exim updates to users, until 27th April. The vulnerabilities were disclosed yesterday, 4 May, a date which Qualys said was agreed with the Exim project.

This timeline inevitably means that many servers were not patched at the time of the announcement. Debian released a [8]security advisory yesterday for its current stable distribution, Buster. At the time of writing, the packages for Debian 9 (Stretch), which is end of life but in long term support, had not yet been updated. All Exim versions before Exim 4.94.2 are vulnerable.

[9]

The Qualys team chose the name 21 Nails as a pun on "21 vulnerabilities in a 'Mail' transfer agent." Nothing to do with coffins, though the new vulnerabilities will reinforce claims that running Postfix, which was designed with security in mind (it was also called Secure Mailer) is a better idea from a security perspective.

Email servers are an obvious attack point because they are of necessity internet-accessible, as evidenced by another recent [10]security incident , called Haffnium, that affected Microsoft Exchange. The number of Exim instances out there is far greater than the number of Exchange servers, although the corporate nature of Exchange may make it a more attractive target. ®

Get our [11]Tech Resources



[1] https://www.theregister.com/2020/08/04/cambridge_uni_decommissioning_hermes_email/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJMVenHLGldrpxA-mkW9yQAAANU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJMVenHLGldrpxA-mkW9yQAAANU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJMVenHLGldrpxA-mkW9yQAAANU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] http://www.securityspace.com/s_survey/data/man.202104/mxsurvey.html

[6] https://regmedia.co.uk/2021/05/05/exim.jpg

[7] https://blog.qualys.com/vulnerabilities-research/2021/05/04/21nails-multiple-vulnerabilities-in-exim-mail-server

[8] https://www.debian.org/security/2021/dsa-4912

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJMVenHLGldrpxA-mkW9yQAAANU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/

[11] https://whitepapers.theregister.com/

shocking

Nate Amsden

Well maybe I shouldn't be shocked, but I am still. Not at the security issue but looking at that MX server survey I had no idea that Exim and Postfix combined had that high of a market share, and that Sendmail was at 40% ~15 years ago and is now at under 4%. I really expected nobody to have more than say 20-25% market share. Personally I have been using Postfix since about 2001 I think. It was suggested to me for a anti virus solution I was looking to deploy at the time and just haven't had a need to look at anything else.

I went off to look at sendmail.org, and wow they are old school(except they seem to be operating under the "ProofPoint" brand not sure when that happened), just read the stuff under the "Contact us" section. Also it's the first reference to a FTP server I have seen on a website in a long time(I have nothing against ftp myself other than it is funky to work through firewalls).

I still prefer text email myself and my personal email server does strip html off of incoming emails automatically which can sometimes make things difficult (and in very rare occasions impossible as in the entire message is empty) to read. But it certainly brings back memories of an earlier era(an era that was much more fun for me computing wise anyway).

For work my org uses office 365 (and hosted exchange at rack space prior), MS introduced breaking changes in the OWA client which I use for most of my mail which makes text based email composing impossible. Reported it almost 2 years ago and last I checked it was still broken (the behavior being new line characters are broken making the entire email be one long line, in many cases totally unreadable. Message is fine in the "outbox" and only gets mangled once it gets beyond that level).

Re: shocking

bombastic bob

Sendmail is the built-in for FreeBSD. I got used to its quirks and it's still supported for integration with other e-mail related things (like Cyrus IMAP), at least last time I integrated the two - which has been a while, yeah.

Exim runs by default on Debian derivatives as well, last I checked. Since it listens locally by default, it's probably not a problem unless you open up the listening ports for LAN or (worse) Internet access.

(verified, Devuan recent distro running exim4, listening port 25 only on 127.0.0.1 and ::1, default out of the box config for mail as I recall)

Re: shocking

ravioli

"Sendmail was at 40% ~15 years ago and is now at under 4%"

Because it's awfully unreliable for what the world wants to use email for now.

cPanel and WHM use Exim, how fast did they patch this? Unbelievable. Just goes to show how we rely on all this software and it could be the weakest link in the chain.

Sheer, blind luck...

Martin Gregorie

Phew, dodged all those nasty Sendmail bullets!

And all because I run Postfix on all my computers including my Raspberry Pi.

Years back, when I was running Fedora 1, if it wasn't still RedHat 7.2, I tried to customise Sendmail by working from the O'Reilly Sendmail book. That most be the worst book they ever published, because an entire section was missing. That meant I couldn't get my head round Sendmail and, being too tight to buy another massive book, I ripped out Sendmail, dropped in Postfix and have never looked back.

So, when I bought my first RPi, naturally I slapped Postfix onto it, added the standard configuration I use on every machine except my house server. One reboot later and it 'just ran' and has continued to do so without any configuration changes despite successive upgrades from Wheezy to Buster.

All of this has happened before

Gordon Shumway

and all of this will happen again.

https://forums.theregister.com/forum/all/2019/09/06/exim_vulnerability_patch/#c_3864984

I still use exim

Lunatic Looking For Asylum

Been using it since 1993 ish.

Just been and compiled and rolled out the new release. Ended up having to do a lot of reading and farting around.

Exim has copious documentation but it is really difficult to digest. Most of the problems today weren't with the compile, it was trying to find what I needed to do to the configuration file so that it would used de-tainted data.

What's de-tainted data ? I hear you all cry. In their wisdom the Exim developers decided that any data that could possibly come from the outside world was dangerous and couldn't be used directly in, for example the name of a file. Seems like a good plan but they didn't tell anybody they were doing this, they just rolled it out and mentioned it in the release notes (not even at the top of the release notes either). Consequently the mailing list was flooded with people screaming because their 'working for decades' configs suddenly stopped.

It's generally been accepted thet the exim devs could have handled the release better.

It's particularly galling that while the devs were busy looking at the tainted data splinter they missed the *()&ing planks that today's release is hopefully in mitigation of.

It does make me wonder what else they have missed and has dented my (and I suspect a lot of other postmastes) confidence in the product.

Who do they believe they are?

LDS

Exchange?

Remember though that
THERE IS NO GENERAL RULE FOR CONVERTING A LIST INTO A SCALAR.
-- Larry Wall in the perl man page