Executive brief
Exim contains a buffer overflow vulnerability in the base64d function of its SMTP listener. By sending a handcrafted message, a remote attacker can trigger the overflow to execute arbitrary code.
Affected products
- Exim Exim before 4.90.1
- Canonical Ubuntu Linux 14.04, 16.04, 17.10
- Debian Debian Linux
Timeline
- 2018-02-05: patched: Patch committed to Exim git repository.
- 2018-02-07: disclosed: Initial disclosure on OSS-security mailing list.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.