Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-5671

Опубликовано: 31 окт. 2012
Источник: nvd
CVSS2: 6.8
EPSS Средний

Описание

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:exim:exim:4.70:*:*:*:*:*:*:*
cpe:2.3:a:exim:exim:4.71:*:*:*:*:*:*:*
cpe:2.3:a:exim:exim:4.72:*:*:*:*:*:*:*
cpe:2.3:a:exim:exim:4.73:*:*:*:*:*:*:*
cpe:2.3:a:exim:exim:4.74:*:*:*:*:*:*:*
cpe:2.3:a:exim:exim:4.75:*:*:*:*:*:*:*
cpe:2.3:a:exim:exim:4.76:*:*:*:*:*:*:*
cpe:2.3:a:exim:exim:4.77:*:*:*:*:*:*:*
cpe:2.3:a:exim:exim:4.80:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.35729
Средний

6.8 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 13 лет назад

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.

redhat
больше 13 лет назад

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.

debian
больше 13 лет назад

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in ...

github
больше 3 лет назад

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.

EPSS

Процентиль: 97%
0.35729
Средний

6.8 Medium

CVSS2

Дефекты

CWE-119