meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, August 8th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 8 August 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Exim Vuln; DockDockGo and Microsoft; Emergency Alerts; Slack Hash Leak; Zimbra flaw exploited

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, August 8, 2020 edition of the Sands and its Storm Center's Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:13.6

Let's start today with patches or vulnerabilities. And first of all, with the mail server, Exim.

0:21.1

Xim, a very popular mail server, comes preinstalled on many Linux systems.

0:26.0

I think I've seen numbers of like 57% of all on-premise mail servers using XM.

0:33.4

Well, the problem here is that XM silently patched a vulnerability that may lead to a buffer overflow.

0:41.5

The vulnerability has been assigned CVE 2020-37-452, and as I'm recording this, I'm not seeing an official

0:51.1

advisory on XM's website, but you are okay if you're running XM version 495 or later.

1:01.8

A GitHub repository has been published with details about the vulnerability.

1:07.6

And of course, by not making this update as security relevant update, many Linux distributions

1:14.0

have not yet rolled out updated packages to fix this problem.

1:20.5

And your vulnerability scanners probably won't flag it either because it wasn't really

1:25.6

known as a vulnerability.

1:30.9

To be exploitable, XM has to be configured to resolve sender host names. The attacker would then send an email and as the mail

1:37.8

server resolves the host name name server would deliver the exploit.

1:45.8

With the GitHub repository released with details, developing an actual exploit,

1:50.2

should not be terribly hard.

1:52.6

So watch out for updates and apply them as they become available.

1:56.2

As a workaround, you may try disabling sender host name resolution if that's not already

2:03.0

disabled.

2:05.6

Duck, Duck Go is responding to criticism that its privacy-focused browser did not block

2:13.8

tracking scripts from Microsoft.

2:16.4

This is not an issue with the Duck, dot go search engine,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.