An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | Feb 21, 2018 | Feb 8, 2018 |
| Amazon_linux | — | Upgrade exim | Mar 9, 2018 | Feb 8, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 8, 2018 |
| Debian | — | Upgrade exim4 | Feb 12, 2018 | Feb 8, 2018 |
| Exim | — | Upgrade Exim to version 4.90.1 | Jun 7, 2019 | Feb 8, 2018 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Mar 7, 2018 | Feb 8, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 8, 2018 |
| Suse | — | Upgrade libspf2-2Upgrade eximstats-htmlUpgrade eximonUpgrade libspf2-develUpgrade eximUpgrade libspf2-tools | Feb 20, 2018 | Feb 8, 2018 |
| Ubuntu | — | Upgrade exim4-daemon-lightUpgrade exim4-daemon-heavy | Feb 13, 2018 | Feb 8, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub