Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16943

Опубликовано: 23 нояб. 2017
Источник: redhat
CVSS3: 9.8

Описание

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

Меры по смягчению последствий

if you are running Exim 4.88 or newer, then in the main section of your Exim configuration, set: chunking_advertise_hosts = This disables advertising the ESMTP CHUNKING extension, making the BDAT verb unavailable and avoids letting an attacker apply the logic.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5eximNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1517680exim: use-after-free in receive_msg function via vectors involving BDAT commands

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

CVSS3: 9.8
nvd
около 8 лет назад

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

CVSS3: 9.8
debian
около 8 лет назад

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 ...

suse-cvrf
около 8 лет назад

Security update for exim

CVSS3: 9.8
github
больше 3 лет назад

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

9.8 Critical

CVSS3