Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note that at this time upstream has released a patch (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21), but it is not known if a new point release is available that addresses this issue at this time.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | Sep 20, 2017 | Jun 19, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 19, 2017 |
| Debian | — | Upgrade exim4 | Jun 21, 2017 | Jun 19, 2017 |
| Exim | — | Upgrade Exim to version 4.87.1 | Jun 7, 2019 | Jun 19, 2017 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Oct 30, 2017 | Jun 19, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 19, 2017 |
| Suse | — | Upgrade eximstats-htmlUpgrade libspf2-develUpgrade eximUpgrade libspf2-2Upgrade libspf2-toolsUpgrade eximon | Jun 20, 2017 | Jun 19, 2017 |
| Ubuntu | — | Upgrade exim4-daemon-heavyUpgrade exim4-daemon-light | Jun 19, 2017 | Jun 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub