Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7m4v-cwm7-4f2m

Опубликовано: 04 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

EPSS

Процентиль: 97%
0.33449
Средний

5.4 Medium

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 5.4
ubuntu
12 месяцев назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CVSS3: 3.7
redhat
12 месяцев назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CVSS3: 5.4
nvd
12 месяцев назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CVSS3: 5.4
debian
12 месяцев назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, an ...

suse-cvrf
11 месяцев назад

Security update for exim

EPSS

Процентиль: 97%
0.33449
Средний

5.4 Medium

CVSS3

Дефекты

CWE-116