Описание
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| exim4 | fixed | 4.99-7 | package | |
| exim4 | not-affected | trixie | package | |
| exim4 | not-affected | bookworm | package | |
| exim4 | not-affected | bullseye | package |
Примечания
https://www.openwall.com/lists/oss-security/2025/12/11/2
https://code.exim.org/exim/exim/commit/4a11617127599c2a40552f5f7e9bf0e863f10e8d
https://www.openwall.com/lists/oss-security/2025/12/18/3
EPSS
Связанные уязвимости
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
Exim before 4.99.1 allows remote heap corruption that will be further described on 2025-12-18.
Уязвимость почтового сервера Exim, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю вызвать отказ в обслуживании
EPSS