PT-2017-10953 · Exim+3 · Exim+3
Published
2017-06-19
·
Updated
2024-06-15
·
CVE-2017-1000369
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Exim versions 4.89 and earlier
Description
The issue allows attackers to cause arbitrary code execution by utilizing multiple "-p" command line arguments in conjunction with other problems. This can lead to memory allocation issues, as the allocated memory is never freed.
Recommendations
For Exim versions 4.89 and earlier, apply the patch released by upstream (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21) to address the issue.
Exploit
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Exim
Suse
Ubuntu