Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exim4 | Jul 30, 2024 | May 2, 2005 |
| Freebsd | — | Upgrade exim-mysqlUpgrade exim-postgresqlUpgrade exim-ldap2Upgrade exim-ldapUpgrade eximUpgrade exim-sa-exim | Dec 10, 2025 | Jan 5, 2005 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Oct 30, 2017 | May 2, 2005 |
| Ubuntu | — | Upgrade exim4-daemon-heavy | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub