PT-2017-10953 · Exim+3 · Exim+3

Published

2017-06-19

·

Updated

2024-06-15

·

CVE-2017-1000369

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Exim versions 4.89 and earlier
Description The issue allows attackers to cause arbitrary code execution by utilizing multiple "-p" command line arguments in conjunction with other problems. This can lead to memory allocation issues, as the allocated memory is never freed.
Recommendations For Exim versions 4.89 and earlier, apply the patch released by upstream (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21) to address the issue.

Exploit

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1409
CVE-2017-1000369
DLA-1001-1
DSA-3888-1
OPENSUSE-SU-2017_1625-1
OPENSUSE-SU-2017_2289-1
OPENSUSE-SU-2021:0677-1
OPENSUSE-SU-2021:0753-1
OPENSUSE-SU-2021:0754-1
OPENSUSE-SU-2021_0677-1
OPENSUSE-SU-2024:10746-1
USN-3322-1

Affected Products

Alt Linux
Exim
Suse
Ubuntu