PT-2012-6069 · Exim+2 · Exim+2

Phil Pennock

·

Published

2012-10-27

·

Updated

2024-06-15

·

CVE-2012-5671

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Exim versions 4.70 through 4.80
Description The issue is a heap-based buffer overflow in the dkim exim query dns txt function, which can be exploited by remote attackers to execute arbitrary code. This can occur when DKIM support is enabled and specific settings, acl smtp connect and acl smtp rcpt, are not configured to disable DKIM verification. The attack vector involves an email from a malicious DNS server.
Recommendations For Exim versions 4.70 through 4.80, consider disabling DKIM support or setting acl smtp connect and acl smtp rcpt to "warn control = dkim disable verify" to mitigate the risk of exploitation.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1684
CVE-2012-5671
DSA-2566-1
OPENSUSE-SU-2012_1404-1
OPENSUSE-SU-2024:10017-1

Affected Products

Alt Linux
Exim
Suse