Описание
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
Ссылки
- Patch
- Broken Link
- Vendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
EPSS
4.8 Medium
CVSS3
9.1 Critical
CVSS3
Дефекты
Связанные уязвимости
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
In Exim before 4.99.2, when the SPA authentication driver is used with ...
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
Уязвимость почтового сервера Exim, связанная с отсутствием инициализации ресурса, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации
EPSS
4.8 Medium
CVSS3
9.1 Critical
CVSS3