<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:libspf2_project:libspf2:-:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3alibspf2_projectlibspf2-/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 13:51:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3alibspf2_projectlibspf2-/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in Exim Mail Transfer Agent</title><link>https://feed.craftedsignal.io/briefs/2026-09-exim-vulnerabilities/</link><pubDate>Mon, 21 Sep 2026 13:51:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-exim-vulnerabilities/</guid><description>Multiple vulnerabilities in the Exim mail transfer agent allow remote, unauthenticated attackers to perform memory corruption, security constraint bypass, and denial-of-service.</description><content:encoded><![CDATA[<p>The Exim mail transfer agent is affected by multiple security vulnerabilities (CVE-2023-42114, CVE-2023-42115, CVE-2023-42116, CVE-2023-42117, CVE-2023-42118, and CVE-2023-42119). These flaws allow a remote, unauthenticated attacker to exploit the software via crafted network communications. Successful exploitation may result in memory corruption, the bypass of existing security controls, unauthorized disclosure or manipulation of data, and the induction of denial-of-service states. Defenders should identify all instances of Exim within their environment and ensure they are patched to the latest version provided by their distribution or vendor to mitigate these risks.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities can lead to full compromise of the Exim process, allowing for potential data exfiltration, service disruption, and manipulation of email traffic. Organizations relying on Exim for mail routing are at risk of service outages and unauthorized access to sensitive communications.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and patching of all internet-facing Exim instances. Monitor mail server infrastructure for abnormal memory usage or service restarts, which may indicate attempted exploitation or crash-inducing behavior.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>