Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
2010-12-14T16:00:04.163
2025-04-11T00:51:21.963
Deferred
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | exim | exim | < 4.70 | Yes |
Operating System | opensuse | opensuse | 11.1 | Yes |
Operating System | opensuse | opensuse | 11.2 | Yes |
Operating System | opensuse | opensuse | 11.3 | Yes |
Operating System | debian | debian_linux | 5.0 | Yes |
Operating System | canonical | ubuntu_linux | 6.06 | Yes |
Operating System | canonical | ubuntu_linux | 8.04 | Yes |
Operating System | canonical | ubuntu_linux | 9.10 | Yes |