Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-4344

Опубликовано: 07 дек. 2010
Источник: redhat
CVSS2: 7.5

Описание

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-78

7.5 High

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 14 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

CVSS3: 9.8
nvd
больше 14 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

CVSS3: 9.8
debian
больше 14 лет назад

Heap-based buffer overflow in the string_vformat function in string.c ...

github
около 3 лет назад

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

oracle-oval
больше 14 лет назад

ELSA-2010-0970: exim security update (CRITICAL)

7.5 High

CVSS2