Vulnerability Description
A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Exim | Exim | < 4.97 |
| Fedoraproject | Fedora | 35 |
Related Weaknesses (CWE)
References
- https://bugs.exim.org/show_bug.cgi?id=2915PatchVendor Advisory
- https://git.exim.org/exim.git/commit/4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2PatchVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://vuldb.com/?id.211073Third Party Advisory
- https://bugs.exim.org/show_bug.cgi?id=2915PatchVendor Advisory
- https://git.exim.org/exim.git/commit/4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/10/msg00029.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://vuldb.com/?id.211073Third Party Advisory
FAQ
What is CVE-2022-3559?
CVE-2022-3559 is a vulnerability with a CVSS score of 4.6 (MEDIUM). A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the pa...
How severe is CVE-2022-3559?
CVE-2022-3559 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3559?
Check the references section above for vendor advisories and patch information. Affected products include: Exim Exim, Fedoraproject Fedora.