Описание
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
Ссылки
- Broken Link
- Broken Link
- Issue TrackingPatch
- Mailing ListPatch
- Mailing ListPatch
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken LinkVendor Advisory
- Broken LinkVendor Advisory
- Broken LinkVendor Advisory
- Broken LinkVendor Advisory
- Broken LinkVendor Advisory
- Broken Link
- Mailing ListThird Party Advisory
- ExploitMailing List
- Third Party AdvisoryUS Government Resource
- Third Party Advisory
- ExploitMailing List
- Broken LinkExploitPatch
- Broken Link
Уязвимые конфигурации
Одно из
Одно из
EPSS
9.8 Critical
CVSS3
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
Heap-based buffer overflow in the string_vformat function in string.c ...
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
EPSS
9.8 Critical
CVSS3
9.3 Critical
CVSS2