Executive brief
Exim contains a heap-based buffer overflow in the string_vformat function in string.c. The vulnerability is triggered by a long EHLO command, allowing for remote code execution.
Affected products
- Exim Exim 4.92 through 4.92.2
Timeline
- 2019-09-27: advisory: Vendor advisory published via mailing list
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: disclosed: NVD publication date