Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-39929

Опубликовано: 04 июл. 2024
Источник: debian
EPSS Средний

Описание

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
exim4fixed4.98~RC3-2package

Примечания

  • https://git.exim.org/exim.git/commit/6ce5c70cff8989418e05d01fd2a57703007a6357 (exim-4.98-RC3)

  • https://git.exim.org/exim.git/commit/1b3209b0577a9327ebb076f3b32b8a159c253f7b (exim-4.98-RC3)

  • https://bugs.exim.org/show_bug.cgi?id=3099#c4

EPSS

Процентиль: 97%
0.33449
Средний

Связанные уязвимости

CVSS3: 5.4
ubuntu
12 месяцев назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CVSS3: 3.7
redhat
12 месяцев назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CVSS3: 5.4
nvd
12 месяцев назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

suse-cvrf
11 месяцев назад

Security update for exim

CVSS3: 5.4
redos
12 месяцев назад

Уязвимость exim

EPSS

Процентиль: 97%
0.33449
Средний