PT-2011-3355 · Exim+1 · Exim+1

John R. Levine

+1

·

Publicado

2011-10-05

·

Atualizado

2024-06-15

·

CVE-2011-1764

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.76
Description The issue is related to a format string vulnerability in the dkim exim verify finish function. This vulnerability might allow remote attackers to execute arbitrary code or cause a denial of service, such as a daemon crash, via format string specifiers in data used in DKIM logging. For example, an identity field containing a % (percent) character could trigger this issue.
Recommendations For versions prior to 4.76, update to version 4.76 or later to resolve the issue. As a temporary workaround, consider restricting the use of format string specifiers in DKIM logging data to minimize the risk of exploitation.

Correção

DoS

RCE

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1764
DSA-2232-1
OPENSUSE-SU-2012_1404-1
OPENSUSE-SU-2024:10017-1

Produtos afetados

Exim
Suse