Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvgg-qcrq-7wr8

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

Ссылки

EPSS

Процентиль: 98%
0.57471
Средний

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 14 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

redhat
больше 14 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

CVSS3: 9.8
nvd
больше 14 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

CVSS3: 9.8
debian
больше 14 лет назад

Heap-based buffer overflow in the string_vformat function in string.c ...

oracle-oval
больше 14 лет назад

ELSA-2010-0970: exim security update (CRITICAL)

EPSS

Процентиль: 98%
0.57471
Средний

Дефекты

CWE-119