PT-2005-1154 · Exim+1 · Exim+1
Philip Hazel
·
Published
2005-01-06
·
Updated
2017-10-11
·
CVE-2005-0021
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Exim versions prior to 4.43
Description
The issue is related to multiple buffer overflows that may allow attackers to execute arbitrary code. This can be triggered via an IPv6 address with more than 8 components using the -be command line option, which causes an overflow in the
host aton function. Another trigger is through the -bh command line option or dnsdb PTR lookup, leading to an overflow in the dns build reverse function.Recommendations
For versions prior to 4.43, update to version 4.43 or later to resolve the issue. As a temporary workaround, consider restricting the use of the -be and -bh command line options until a patch is applied. Additionally, restrict dnsdb PTR lookup to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exim
Red Hat