PT-2017-14649 · Exim+3 · Exim+3
Meh
·
Published
2017-11-23
·
Updated
2024-06-15
·
CVE-2017-16944
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Exim versions 4.88 through 4.89
Description
The issue allows remote attackers to cause a denial of service, resulting in an infinite loop and stack exhaustion. This is achieved through vectors involving BDAT commands and an improper check for a '.' character that signifies the end of the content. The problem is related to the
bdat getc function and the receive msg function in the SMTP daemon.Recommendations
For Exim versions 4.88 and 4.89, consider disabling the
receive msg function or restricting the use of BDAT commands as a temporary workaround until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Use After Free
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Exim
Suse
Ubuntu