The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifying the end of the content, related to the bdat_getc function.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | Dec 18, 2017 | Nov 25, 2017 |
| Amazon_linux | — | Upgrade exim | Dec 22, 2017 | Nov 25, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 25, 2017 |
| Debian | — | Upgrade exim4 | Dec 5, 2017 | Nov 25, 2017 |
| Exim | — | Update Exim to the latest version | Dec 3, 2019 | Nov 25, 2017 |
| Freebsd | — | Upgrade exim | Dec 1, 2017 | Nov 30, 2017 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Mar 7, 2018 | Nov 25, 2017 |
| Smtp Exim | — | Disable the Exim ESMTP CHUNKING extensionUpgrade Exim to version 4.90 | Nov 28, 2017 | Nov 24, 2017 |
| Suse | — | Upgrade libspf2-develUpgrade eximstats-htmlUpgrade eximUpgrade eximonUpgrade libspf2-2Upgrade libspf2-tools | May 7, 2021 | Nov 25, 2017 |
| Ubuntu | — | Upgrade exim4-daemon-lightUpgrade exim4-daemon-heavy | Nov 29, 2017 | Nov 25, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub