PT-2022-5379 · Exim+1 · Exim+1

Published

2022-08-31

·

Updated

2025-05-23

·

CVE-2022-3620

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exim (affected versions not specified)
Description The issue affects the function dmarc dns lookup of the file dmarc.c of the component DMARC Handler. This is related to a use after free condition, which can be exploited by a remote attacker to gain unauthorized access to protected information. The attack may be initiated remotely.
Recommendations Apply a patch to fix this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-06645
BDU:2022-06693
CVE-2022-3620

Affected Products

Exim
Red Os