Junglewise Threat Intelligence

CVE-2018-6789: Exim Buffer Overflow Vulnerability

CVE-2018-6789 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Debian Linux, Exim. Vendors: Debian, Exim, Canonical.

Executive brief

Exim contains a buffer overflow vulnerability in the base64d function of its SMTP listener. By sending a handcrafted message, a remote attacker can trigger the overflow to execute arbitrary code.

Affected products

  • Exim Exim before 4.90.1
  • Canonical Ubuntu Linux 14.04, 16.04, 17.10
  • Debian Debian Linux

Timeline

  • 2018-02-05: patched: Patch committed to Exim git repository.
  • 2018-02-07: disclosed: Initial disclosure on OSS-security mailing list.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats