The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifying the end of the content, related to the bdat_getc function.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-exim | Dec 18, 2017 | Nov 25, 2017 | |
| Amazon_linux | — | amazon-linux-upgrade-exim | Dec 22, 2017 | Nov 25, 2017 |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Nov 25, 2017 | |
| Debian | debian-upgrade-exim4 | Dec 5, 2017 | Nov 25, 2017 | |
| Exim | exim-upgrade-latest | Dec 3, 2019 | Nov 25, 2017 | |
| Freebsd | freebsd-upgrade-package-exim | Dec 1, 2017 | Nov 30, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-mta-exim | Mar 7, 2018 | Nov 25, 2017 | |
| Smtp Exim | exim-upgrade-4_90exim-disable-chunking | Nov 28, 2017 | Nov 24, 2017 | |
| Suse | — | suse-upgrade-eximsuse-upgrade-eximonsuse-upgrade-eximstats-htmlsuse-upgrade-libspf2-2suse-upgrade-libspf2-develsuse-upgrade-libspf2-tools | May 7, 2021 | Nov 25, 2017 |
| Ubuntu | ubuntu-upgrade-exim4-daemon-heavyubuntu-upgrade-exim4-daemon-light | Nov 29, 2017 | Nov 25, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub