Описание
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
exim4 | fixed | 4.98.1-2 | package | |
exim4 | not-affected | bullseye | package |
Примечания
https://exim.org/static/doc/security/CVE-2025-30232.txt
https://lists.exim.org/lurker/message/20250326.140105.6b97555b.en.html
Introduced after: https://code.exim.org/exim/exim/commit/19fdbfb4a2b6ca4a6a96ef52be848f0a23e2414f (exim-4.96-RC0)
Fixed by: https://code.exim.org/exim/exim/commit/be040d7df68a8cbb244aaabc37832984dafcbf55
EPSS
Связанные уязвимости
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.
Уязвимость почтового сервера Exim, связанная с использованием памяти после ее освобождения, позволяющая нарушителю повысить свои привилегии
EPSS