Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-4344

Опубликовано: 14 дек. 2010
Источник: debian
EPSS Средний

Описание

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
exim4fixed4.70-1package

EPSS

Процентиль: 98%
0.61461
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 15 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

redhat
около 15 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

CVSS3: 9.8
nvd
около 15 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

github
больше 3 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

oracle-oval
около 15 лет назад

ELSA-2010-0970: exim security update (CRITICAL)

EPSS

Процентиль: 98%
0.61461
Средний