Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-45185

Опубликовано: 12 мая 2026
Источник: debian
EPSS Низкий

Описание

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
exim4fixed4.99.2-2package

Примечания

  • https://code.exim.org/exim/exim/commit/040c1ce6889f435206677ed532c9a4185cf0bcaf

  • https://www.openwall.com/lists/oss-security/2026/05/12/4

  • https://exim.org/static/doc/security/EXIM-Security-2026-05-01.1/EXIM-Security-2026-05-01.1.txt

  • https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim

EPSS

Процентиль: 66%
0.01225
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CVSS3: 9.8
nvd
3 месяца назад

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CVSS3: 9.8
github
3 месяца назад

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость функции ungetc() компонента BDAT/CHUNKING почтового сервера Exim, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
redos
12 дней назад

Уязвимость exim

EPSS

Процентиль: 66%
0.01225
Низкий