PT-2012-6069 · Exim+2 · Exim+2

Phil Pennock

·

Publicado

2012-10-27

·

Atualizado

2024-06-15

·

CVE-2012-5671

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Exim versions 4.70 through 4.80
Description The issue is a heap-based buffer overflow in the dkim exim query dns txt function, which can be exploited by remote attackers to execute arbitrary code. This can occur when DKIM support is enabled and specific settings, acl smtp connect and acl smtp rcpt, are not configured to disable DKIM verification. The attack vector involves an email from a malicious DNS server.
Recommendations For Exim versions 4.70 through 4.80, consider disabling DKIM support or setting acl smtp connect and acl smtp rcpt to "warn control = dkim disable verify" to mitigate the risk of exploitation.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1684
CVE-2012-5671
DSA-2566-1
OPENSUSE-SU-2012_1404-1
OPENSUSE-SU-2024:10017-1

Produtos afetados

Alt Linux
Exim
Suse