Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exim4 | Jul 30, 2024 | May 2, 2005 |
| Freebsd | — | Upgrade exim-postgresqlUpgrade exim-mysqlUpgrade eximUpgrade exim-ldapUpgrade exim-sa-eximUpgrade exim-ldap2 | Dec 10, 2025 | Jan 5, 2005 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Oct 30, 2017 | May 2, 2005 |
| Ubuntu | — | Upgrade exim4-daemon-heavy | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub