Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-67896

Опубликовано: 14 дек. 2025
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

A flaw was found in Exim. A remote attacker could exploit a heap corruption vulnerability, which is a type of memory error, to potentially cause the system to crash (Denial of Service) or execute unauthorized code. Further details regarding the exploitation method are expected to be released at a later date.

Отчет

This vulnerability is rated Moderate as it allows a remote attacker to exploit a heap corruption flaw. This could lead to a denial of service or arbitrary code execution. This issue impacts Exim in Community Projects, including EPEL and Fedora.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2422034exim: Exim: Remote heap corruption vulnerability

EPSS

Процентиль: 25%
0.00087
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
4 месяца назад

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

CVSS3: 7
nvd
4 месяца назад

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

CVSS3: 7
debian
4 месяца назад

Exim before 4.99.1, with certain non-default rate-limit configurations ...

CVSS3: 6.4
github
4 месяца назад

Exim before 4.99.1 allows remote heap corruption that will be further described on 2025-12-18.

CVSS3: 9.8
fstec
4 месяца назад

Уязвимость почтового сервера Exim, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 25%
0.00087
Низкий

8.2 High

CVSS3