Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
CVSS Details
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade exim | Mar 7, 2017 | Dec 25, 2016 |
| Debian | — | Upgrade exim4 | Dec 26, 2016 | Dec 25, 2016 |
| Exim | — | Upgrade Exim to version 4.87.0 | Jun 7, 2019 | Feb 1, 2017 |
| Freebsd | — | Upgrade exim | Dec 26, 2016 | Dec 25, 2016 |
| Suse | — | Upgrade eximUpgrade eximstats-htmlUpgrade exim-debugsourceUpgrade exim-debuginfoUpgrade eximon-debuginfoUpgrade eximon | Aug 29, 2017 | Dec 25, 2016 |
| Ubuntu | — | Upgrade exim4-daemon-lightUpgrade exim4-daemon-heavy | Jan 6, 2017 | Dec 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub