Описание
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
A vulnerability was found in the Exim package. Exim is vulnerable to bypassing the $mime_filename extension-blocking protection mechanism. This flaw could potentially result in delivering malicious executable attachments to end users, which would require their interaction to run.
Отчет
Exim is not shipped in any Red Hat Offerings.
Ссылки на источники
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, an ...
EPSS
3.7 Low
CVSS3