VPS.NET Cloud Community: Exim Exploit affecting cPanel servers - IMPORTANT - VPS.NET Cloud Community

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Exim Exploit affecting cPanel servers - IMPORTANT Rate Topic: -----

#1 User is offline   nickn 

  • Nick Nelson
  • Group: VPS.NET Management
  • Posts: 189
  • Joined: 26-March 09

Posted 10 December 2010 - 07:35 AM

=============
Summary
=============
A privilege escalation vulnerability exists in Exim, the mail transfer agent used by cPanel & WHM.

-----------------------
Security Rating
-----------------------
This update has been rated as Critical by the cPanel Security team.

Description
-----------------------
Research up to this point indicates the exploit is a buffer overflow vulnerability that takes advantage of the default Exim configuration settings related to altering Exim's runtime configuration file along with overriding the macro definitions in the configuration file. This buffer overflow may lead to arbitrary code execution with the privileges of the user executing the Exim daemon. However, the Exim user retains root privileges when running the -C and -D command line flags. Through the creation of a temporary exim configuration which is processed with the -C or -D flags, the Exim user is able to execute arbitrary commands as root.

Solution
-----------------------
To resolve and work around the issue, for Linux-based systems cPanel has issued new Exim RPMs. The new version of Exim locks configuration file locations to the /etc/exim prefix as well as disabling use of the -D flag. Server Owners are strongly urged to upgrade to the following Exim RPM versions:

• Systems configured to use Maildir: Exim 4.69-25
• Systems configured to use mbox (deprecated): Exim 4.63-4

Exim RPMs will be distributed through cPanel's package management system. All cPanel & WHM servers receiving updates automatically will receive the updated Exim RPM during normal update and maintenance operations (upcp). If you prefer to install the update right now, please run the following in a root shell:

/scripts/eximup

On cPanel & WHM FreeBSD servers, Exim is an unmanaged install performed from the Ports system. To apply a like setup on FreeBSD systems, server administrators will need to perform the following manual configuration:

• Remove WITHOUT_ALT_CONFIG_PREFIX=yes from /etc/make.conf
• Add the following to /var/db/ports/exim/options

WITH_ALT_CONFIG_PREFIX=true
SEDLIST+= -e 's,^(ALT_CONFIG_PREFIX=).*,\1/etc/exim,'
SEDLIST+= -e 's,^\# (DISABLE_D_OPTION=),\1,'

• Change directory to /usr/ports/mail/exim
• Execute 'make deinstall'
• Execute 'make install'

Caution: the above changes have potential to be undone by /scripts/checkmakeconf, and updates to the Exim port. An upcoming version of cPanel & WHM 11.28 will resolve this for FreeBSD users.

References
-----------------------
SecurityLevels < AllDocumentation < TWiki
[exim-dev] Remote root vulnerability in Exim
Nick Nelson

VPS.NET Managing Director

Office: 020 7053 7671
0

#2 User is offline   boeki 

  • I Got Nodes
  • PipPipPip
  • Group: Customers
  • Posts: 233
  • Joined: 26-August 10

Posted 10 December 2010 - 08:50 AM

thanks for the headsup. updating servers now.
0

#3 User is offline   nickn 

  • Nick Nelson
  • Group: VPS.NET Management
  • Posts: 189
  • Joined: 26-March 09

Posted 10 December 2010 - 09:04 AM

I would recommend doing ksplice at the same time :)
Nick Nelson

VPS.NET Managing Director

Office: 020 7053 7671
0

#4 User is offline   boeki 

  • I Got Nodes
  • PipPipPip
  • Group: Customers
  • Posts: 233
  • Joined: 26-August 10

Posted 10 December 2010 - 09:48 AM

my cpanel servers are up-to-date all along.

re ksplice, it says my servers' kernel (cloudlinux) are fully up-to-date.
0

#5 User is offline   paperweight 

  • I Got Nodes
  • PipPipPip
  • Group: Customers
  • Posts: 49
  • Joined: 22-December 09

Posted 12 December 2010 - 01:53 AM

Hmmmmmmm.... the email I received about the urgency of this mentioned cPanel, but did not make it clear that it was only for cPanel... is this only for cPanel or also for ISPmanager? Should I worry about it if I am only running CentOS/ISPmanager?
Server, Heal Thyself!
0

#6 User is offline   anthonysomerset 

  • On Cloud 9
  • PipPipPip
  • Group: Customers
  • Posts: 618
  • Joined: 16-September 09
  • LocationLondon, UK

Posted 12 December 2010 - 09:56 AM

its for anyone running exim

cpanel just happens to be the most common platform where exim is used, debian also uses exim by default

you should only worry if your mail server is exim, if its postfix or sendmail you will be ok for now
0

#7 User is offline   bin_asc 

  • Junior Member
  • PipPipPip
  • Group: Customers
  • Posts: 35
  • Joined: 20-October 10

Posted 12 December 2010 - 04:38 PM

Isn`t this vulnerability only for Debian systems ?
0

#8 User is offline   nickn 

  • Nick Nelson
  • Group: VPS.NET Management
  • Posts: 189
  • Joined: 26-March 09

Posted 12 December 2010 - 06:31 PM

View Postbin_asc, on 12 December 2010 - 04:38 PM, said:

Isn`t this vulnerability only for Debian systems ?


Nope. cPanel has already said that it affects their installs as well.
Nick Nelson

VPS.NET Managing Director

Office: 020 7053 7671
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users