Executive brief
A heap-based buffer overflow exists in the string_vformat function in Exim's string.c. Remote attackers can exploit this via a crafted SMTP session involving multiple MAIL commands and large message headers to execute arbitrary code.
Affected products
- Exim Exim before 4.70
Timeline
- 2010-12-10: disclosed: Initial public disclosure and mailing list discussions.
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-03-25: exploited: Reported as exploited in the wild.