Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16943

Опубликовано: 25 нояб. 2017
Источник: debian

Описание

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
exim4fixed4.89-12package
exim4not-affectedjessiepackage
exim4not-affectedwheezypackage

Примечания

  • https://bugs.exim.org/show_bug.cgi?id=2199

  • https://git.exim.org/exim.git/commitdiff/4e6ae6235c68de243b1c2419027472d7659aa2b4

  • https://lists.exim.org/lurker/message/20171125.034842.d1d75cac.en.html

  • https://twitter.com/philpennock/status/934270613811875840

  • 4.89-10 adds a workaround which disables the affected code by default

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

CVSS3: 9.8
redhat
около 8 лет назад

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

CVSS3: 9.8
nvd
около 8 лет назад

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

suse-cvrf
около 8 лет назад

Security update for exim

CVSS3: 9.8
github
больше 3 лет назад

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.