Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhg4-whcv-f8v4

Опубликовано: 12 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

EPSS

Процентиль: 66%
0.01225
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CVSS3: 9.8
nvd
3 месяца назад

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CVSS3: 9.8
debian
3 месяца назад

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely r ...

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость функции ungetc() компонента BDAT/CHUNKING почтового сервера Exim, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
redos
12 дней назад

Уязвимость exim

EPSS

Процентиль: 66%
0.01225
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416