PT-2025-7615 · Exim+2 · Exim+2

Oscar Bataille

·

Published

2025-02-21

·

Updated

2025-12-18

·

CVE-2025-26794

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exim versions 4.98 through 4.98.0
Description The issue allows remote SQL injection when SQLite hints and ETRN serialization are used. This could potentially allow a remote attacker to perform SQL injection, possibly stealing sensitive data or crashing servers. The vulnerability exists in Exim version 4.98 when specific configurations are used, involving the use of SQLite hints and ETRN serialization.
Recommendations Update to Exim version 4.98.1 or later to prevent exploitation and safeguard data. As a temporary workaround, consider disabling the use of SQLite hints and ETRN serialization until a patch is available. Restrict access to the Exim mail transfer agent to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-01904
CVE-2025-26794
EXIM_CVE_2025_26794
OPENSUSE-SU-2025:14935-1

Affected Products

Astra Linux
Exim
Red Os