Описание
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-40687
- https://code.exim.org/exim/exim/commit/68b963b9f75ca27b38e1c0f8c87037990199f505
- https://exim.org/static/doc/security/CVE-2025-40687.txt
- https://exim.org/static/doc/security/CVE-2026-40687.txt
- https://exim.org/static/doc/security/cve-2026-04.1/CVE2026-40687.assessment
- https://www.openwall.com/lists/oss-security/2026/04/30/21
Связанные уязвимости
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
In Exim before 4.99.2, when the SPA authentication driver is used with ...
Уязвимость почтового сервера Exim, связанная с отсутствием инициализации ресурса, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации