Описание
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 4.99.1-1ubuntu2 |
| esm-infra-legacy/trusty | ignored | changes too intrusive |
| esm-infra-legacy/xenial | ignored | changes too intrusive |
| esm-infra/bionic | ignored | changes too intrusive |
| esm-infra/focal | released | 4.93-13ubuntu1.12+esm1 |
| esm-infra/xenial | ignored | end of ESM support, was needs-triage |
| jammy | released | 4.95-4ubuntu2.7 |
| noble | released | 4.97-4ubuntu4.4 |
| questing | released | 4.98.2-1ubuntu2.1 |
| resolute | released | 4.99.1-1ubuntu1.1 |
Показывать по
4.8 Medium
CVSS3
Связанные уязвимости
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
In Exim before 4.99.2, when the SPA authentication driver is used with ...
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
Уязвимость почтового сервера Exim, связанная с отсутствием инициализации ресурса, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации
4.8 Medium
CVSS3