The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exim4 | Jul 30, 2024 | Sep 4, 2014 |
| Exim | — | Upgrade Exim to version 4.82.0 | Jun 7, 2019 | Sep 4, 2014 |
| Suse | — | Upgrade eximonUpgrade exim-debugsourceUpgrade eximon-debuginfoUpgrade exim-debuginfoUpgrade eximstats-htmlUpgrade exim | Dec 18, 2015 | Aug 11, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub