PT-2005-1154 · Exim+1 · Exim+1

Philip Hazel

·

Published

2005-01-06

·

Updated

2017-10-11

·

CVE-2005-0021

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.43
Description The issue is related to multiple buffer overflows that may allow attackers to execute arbitrary code. This can be triggered via an IPv6 address with more than 8 components using the -be command line option, which causes an overflow in the host aton function. Another trigger is through the -bh command line option or dnsdb PTR lookup, leading to an overflow in the dns build reverse function.
Recommendations For versions prior to 4.43, update to version 4.43 or later to resolve the issue. As a temporary workaround, consider restricting the use of the -be and -bh command line options until a patch is applied. Additionally, restrict dnsdb PTR lookup to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0021
DSA-635-1
DSA-637-1
RHSA-2005:025
RHSA-2005_025

Affected Products

Exim
Red Hat