CVE-2022-37451
published 2022-08-06CVE-2022-37451: Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.55%
83.1th percentile
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | exim4 | < exim4 4.95-4 (bookworm) | exim4 4.95-4 (bookworm) |
| exim | exim | < 4.96 | 4.96 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-968g-c3p8-6hvf: Exim before 4
ghsa_unreviewed·2022-08-07
CVE-2022-37451 [HIGH] CWE-763 GHSA-968g-c3p8-6hvf: Exim before 4
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
OSV
CVE-2022-37451: Exim before 4
osv·2022-08-06·CVSS 7.5
CVE-2022-37451 [HIGH] CVE-2022-37451: Exim before 4
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
Red Hat
Exim: Exim before 4.96 has an invalid free in pam_converse
vendor_redhat·2022-08-06·CVSS 7.5
CVE-2022-37451 [HIGH] CWE-763 Exim: Exim before 4.96 has an invalid free in pam_converse
Exim: Exim before 4.96 has an invalid free in pam_converse
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
Statement: This flaw affects Community Projects only; no supported Red Hat products are affected.
Debian
CVE-2022-37451: exim4 - Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because...
vendor_debian·2022·CVSS 7.5
CVE-2022-37451 [HIGH] CVE-2022-37451: exim4 - Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because...
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
Scope: local
bookworm: resolved (fixed in 4.95-4)
bullseye: resolved
forky: resolved (fixed in 4.95-4)
sid: resolved (fixed in 4.95-4)
trixie: resolved (fixed in 4.95-4)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cwe.mitre.org/data/definitions/762.htmlhttps://github.com/Exim/exim/commit/51be321b27825c01829dffd90f11bfff256f7e42https://github.com/Exim/exim/compare/exim-4.95...exim-4.96https://github.com/Exim/exim/wiki/EximSecurityhttps://github.com/ivd38/exim_invalid_freehttps://lists.exim.org/lurker/message/20220625.141825.d6de6074.en.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LETR5CVDPFOFQHXCJP6NFLG52JZHQYDY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XSWDF4QEXD4TDWQLYQOWCHBJKTDQR4Z7/https://www.exim.org/static/doc/security/https://www.openwall.com/lists/oss-security/2022/08/06/1https://cwe.mitre.org/data/definitions/762.htmlhttps://github.com/Exim/exim/commit/51be321b27825c01829dffd90f11bfff256f7e42https://github.com/Exim/exim/compare/exim-4.95...exim-4.96https://github.com/Exim/exim/wiki/EximSecurityhttps://github.com/ivd38/exim_invalid_freehttps://lists.exim.org/lurker/message/20220625.141825.d6de6074.en.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LETR5CVDPFOFQHXCJP6NFLG52JZHQYDY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XSWDF4QEXD4TDWQLYQOWCHBJKTDQR4Z7/https://www.exim.org/static/doc/security/https://www.openwall.com/lists/oss-security/2022/08/06/1
2022-08-06
Published