Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-39929

Опубликовано: 04 июл. 2024
Источник: redhat
CVSS3: 3.7
EPSS Средний

Описание

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

A vulnerability was found in the Exim package. Exim is vulnerable to bypassing the $mime_filename extension-blocking protection mechanism. This flaw could potentially result in delivering malicious executable attachments to end users, which would require their interaction to run.

Отчет

Exim is not shipped in any Red Hat Offerings.

Дополнительная информация

Статус:

Important
Дефект:
CWE-693
https://bugzilla.redhat.com/show_bug.cgi?id=2295819exim: exim: Incorrect parsing of multiline rfc2231 header filename

EPSS

Процентиль: 99%
0.41225
Средний

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 2 лет назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CVSS3: 5.4
nvd
около 2 лет назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CVSS3: 5.4
debian
около 2 лет назад

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, an ...

suse-cvrf
около 2 лет назад

Security update for exim

CVSS3: 5.4
redos
около 2 лет назад

Уязвимость exim

EPSS

Процентиль: 99%
0.41225
Средний

3.7 Low

CVSS3