Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exim4 | Jul 30, 2024 | Oct 5, 2011 |
| Exim | — | Upgrade Exim to version 4.75.0 | Dec 3, 2019 | Oct 5, 2011 |
| Freebsd | — | Upgrade exim | Dec 10, 2025 | May 14, 2011 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Oct 30, 2017 | Oct 4, 2011 |
| Suse | — | Upgrade eximUpgrade eximstats-htmlUpgrade exim-debuginfoUpgrade exim-debugsourceUpgrade eximonUpgrade eximon-debuginfo | Feb 17, 2015 | Oct 4, 2011 |
| Ubuntu | — | Upgrade exim4-daemon-customUpgrade exim4-daemon-heavyUpgrade exim4-daemon-light | Nov 8, 2024 | Oct 5, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub