MidnightBSD

Advisories for exim

CVE-2010-2023 MEDIUM

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
exim exim 4.10
exim exim 4.68
exim exim 4.33
exim exim 4.40
exim exim 4.52
exim exim 4.62
exim exim 4.34
exim exim 4.53
exim exim 4.65
exim exim 4.61
exim exim 4.30
exim exim 4.63
exim exim 4.70
exim exim 4.54
exim exim 4.67
exim exim 4.24
exim exim 4.50
exim exim 4.60
exim exim 4.20
exim exim 4.43
exim exim *
exim exim 4.42
exim exim 4.69
exim exim 4.32
exim exim 4.31
exim exim 4.64
exim exim 4.21
exim exim 4.22
exim exim 4.51
exim exim 4.44
exim exim 4.41
exim exim 4.66
exim exim 4.23
CVE-2010-2024 MEDIUM

transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
exim exim 4.10
exim exim 4.68
exim exim 4.33
exim exim 4.40
exim exim 4.52
exim exim 4.62
exim exim 4.34
exim exim 4.53
exim exim 4.65
exim exim 4.61
exim exim 4.30
exim exim 4.63
exim exim 4.70
exim exim 4.54
exim exim 4.67
exim exim 4.24
exim exim 4.50
exim exim 4.60
exim exim 4.20
exim exim 4.43
exim exim *
exim exim 4.42
exim exim 4.69
exim exim 4.32
exim exim 4.31
exim exim 4.64
exim exim 4.21
exim exim 4.22
exim exim 4.51
exim exim 4.44
exim exim 4.41
exim exim 4.66
exim exim 4.23
CVE-2010-4344 HIGH

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,CWE-787,

Products Affected

Vendor Product Version
exim exim 4.10
exim exim 4.68
exim exim 4.40
debian debian_linux 5.0
exim exim 4.01
exim exim 2.11
exim exim 4.53
exim exim 4.12
exim exim 3.16
exim exim 4.63
exim exim 4.54
exim exim 4.67
exim exim 3.00
exim exim 4.03
exim exim 4.14
exim exim 3.01
exim exim 3.36
exim exim 4.60
exim exim 3.21
exim exim 4.20
exim exim 3.14
exim exim 4.43
exim exim *
exim exim 3.34
exim exim 3.32
exim exim 2.10
exim exim 3.30
exim exim 4.11
exim exim 3.11
exim exim 4.02
exim exim 4.66
exim exim 3.02
opensuse opensuse 11.2
exim exim 4.00
exim exim 4.23
exim exim 4.04
exim exim 4.33
exim exim 3.22
exim exim 4.52
exim exim 4.62
exim exim 3.31
exim exim 4.34
exim exim 4.65
exim exim 4.61
exim exim 4.30
exim exim 2.12
exim exim 3.20
exim exim 3.13
opensuse opensuse 11.3
exim exim 3.15
exim exim 3.03
exim exim 4.24
exim exim 4.50
exim exim 3.35
exim exim 3.10
exim exim 4.42
canonical ubuntu_linux 8.04
exim exim 3.33
exim exim 4.32
canonical ubuntu_linux 6.06
exim exim 3.12
exim exim 4.31
exim exim 4.64
exim exim 4.05
exim exim 4.21
exim exim 4.22
exim exim 4.51
canonical ubuntu_linux 9.10
exim exim 4.44
opensuse opensuse 11.1
exim exim 4.41
CVE-2010-4345 MEDIUM

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,CWE-77,

Products Affected

Vendor Product Version
exim exim 4.10
exim exim 4.68
exim exim 4.40
debian debian_linux 5.0
exim exim 4.01
exim exim 2.11
exim exim 4.53
exim exim 4.12
exim exim 3.16
exim exim 4.63
exim exim 4.70
exim exim 4.54
exim exim 4.67
exim exim 3.00
exim exim 4.03
exim exim 4.14
exim exim 3.01
exim exim 3.36
exim exim 4.60
exim exim 3.21
exim exim 4.20
exim exim 3.14
exim exim 4.43
canonical ubuntu_linux 10.10
exim exim *
exim exim 3.34
exim exim 4.69
exim exim 3.32
exim exim 2.10
exim exim 3.30
exim exim 4.11
exim exim 3.11
exim exim 4.02
exim exim 4.66
exim exim 3.02
opensuse opensuse 11.2
exim exim 4.00
exim exim 4.23
exim exim 4.04
exim exim 4.33
exim exim 3.22
canonical ubuntu_linux 10.04
exim exim 4.52
exim exim 4.62
exim exim 3.31
exim exim 4.34
exim exim 4.65
exim exim 4.61
exim exim 4.30
exim exim 2.12
exim exim 3.20
exim exim 3.13
opensuse opensuse 11.3
exim exim 3.15
exim exim 3.03
exim exim 4.24
exim exim 4.50
exim exim 3.35
exim exim 3.10
exim exim 4.71
exim exim 4.42
canonical ubuntu_linux 8.04
exim exim 3.33
exim exim 4.32
canonical ubuntu_linux 6.06
exim exim 3.12
exim exim 4.31
exim exim 4.64
exim exim 4.05
exim exim 4.21
exim exim 4.22
exim exim 4.51
canonical ubuntu_linux 9.10
exim exim 4.44
opensuse opensuse 11.1
exim exim 4.41
CVE-2011-0017 MEDIUM

The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,CWE-59,

Products Affected

Vendor Product Version
exim exim 4.10
exim exim 4.68
exim exim 4.40
exim exim 4.01
exim exim 2.11
exim exim 4.53
exim exim 4.12
exim exim 3.16
exim exim 4.63
exim exim 4.70
exim exim 4.54
exim exim 4.67
exim exim 3.00
exim exim 4.03
exim exim 4.14
exim exim 3.01
exim exim 3.36
exim exim 4.60
exim exim 3.21
exim exim 4.20
exim exim 3.14
exim exim 4.43
exim exim *
exim exim 3.34
exim exim 4.69
exim exim 3.32
exim exim 2.10
exim exim 3.30
exim exim 4.11
exim exim 3.11
exim exim 4.02
exim exim 4.66
exim exim 3.02
exim exim 4.00
exim exim 4.23
exim exim 4.04
exim exim 4.33
exim exim 3.22
exim exim 4.52
exim exim 4.62
exim exim 3.31
exim exim 4.34
exim exim 4.65
exim exim 4.61
exim exim 4.30
exim exim 2.12
exim exim 3.20
exim exim 3.13
exim exim 3.15
exim exim 3.03
exim exim 4.24
exim exim 4.50
exim exim 3.35
exim exim 3.10
exim exim 4.71
exim exim 4.42
exim exim 3.33
exim exim 4.32
exim exim 3.12
exim exim 4.31
exim exim 4.64
exim exim 4.05
exim exim 4.21
exim exim 4.22
exim exim 4.51
exim exim 4.44
exim exim 4.41
CVE-2011-1407 HIGH

The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
exim exim 4.70
exim exim 4.73
exim exim 4.75
exim exim 4.72
exim exim 4.74
exim exim 4.71
CVE-2011-1764 HIGH

Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-134,

Products Affected

Vendor Product Version
exim exim 4.10
exim exim 4.68
exim exim 4.40
exim exim 4.01
exim exim 2.11
exim exim 4.53
exim exim 4.12
exim exim 3.16
exim exim 4.63
exim exim 4.70
exim exim 4.54
exim exim 4.67
exim exim 4.73
exim exim 3.00
exim exim 4.03
exim exim 4.14
exim exim 3.01
exim exim 3.36
exim exim 4.60
exim exim 3.21
exim exim 4.20
exim exim 3.14
exim exim 4.43
exim exim *
exim exim 3.34
exim exim 4.69
exim exim 3.32
exim exim 2.10
exim exim 4.72
exim exim 3.30
exim exim 4.11
exim exim 3.11
exim exim 4.02
exim exim 4.66
exim exim 3.02
exim exim 4.00
exim exim 4.23
exim exim 4.04
exim exim 4.33
exim exim 3.22
exim exim 4.52
exim exim 4.62
exim exim 3.31
exim exim 4.34
exim exim 4.65
exim exim 4.61
exim exim 4.30
exim exim 2.12
exim exim 3.20
exim exim 3.13
exim exim 3.15
exim exim 3.03
exim exim 4.24
exim exim 4.50
exim exim 3.35
exim exim 4.74
exim exim 3.10
exim exim 4.71
exim exim 4.42
exim exim 3.33
exim exim 4.32
exim exim 3.12
exim exim 4.31
exim exim 4.64
exim exim 4.05
exim exim 4.21
exim exim 4.22
exim exim 4.51
exim exim 4.44
exim exim 4.41
CVE-2012-5671 MEDIUM

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
exim exim 4.77
exim exim 4.70
exim exim 4.73
exim exim 4.80
exim exim 4.76
exim exim 4.75
exim exim 4.72
exim exim 4.74
exim exim 4.71
CVE-2014-2957 MEDIUM

The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
exim exim 4.10
exim exim 4.68
exim exim 4.40
exim exim 4.01
exim exim 4.53
exim exim 4.12
exim exim 4.63
exim exim 4.70
exim exim 4.54
exim exim 4.67
exim exim 4.73
exim exim 4.80
exim exim 4.03
exim exim 4.14
exim exim 4.60
exim exim 4.20
exim exim 4.43
exim exim *
exim exim 4.69
exim exim 4.72
exim exim 4.77
exim exim 4.11
exim exim 4.02
exim exim 4.66
exim exim 4.00
exim exim 4.23
exim exim 4.04
exim exim 4.33
exim exim 4.52
exim exim 4.62
exim exim 4.34
exim exim 4.65
exim exim 4.61
exim exim 4.30
exim exim 4.24
exim exim 4.50
exim exim 4.74
exim exim 4.71
exim exim 4.42
exim exim 4.75
exim exim 4.32
exim exim 4.31
exim exim 4.64
exim exim 4.05
exim exim 4.21
exim exim 4.22
exim exim 4.51
exim exim 4.44
exim exim 4.76
exim exim 4.41
exim exim 4.80.1
CVE-2014-2972 MEDIUM

expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-189,

Products Affected

Vendor Product Version
exim exim 4.10
exim exim 4.68
exim exim 4.82
exim exim 4.40
exim exim 4.01
exim exim 4.53
exim exim 4.12
exim exim 4.63
exim exim 4.70
exim exim 4.54
exim exim 4.67
exim exim 4.73
exim exim 4.80
exim exim 4.03
exim exim 4.14
exim exim 4.60
exim exim 4.20
exim exim 4.43
exim exim *
exim exim 4.69
exim exim 4.72
exim exim 4.77
exim exim 4.11
exim exim 4.02
exim exim 4.66
exim exim 4.00
exim exim 4.23
exim exim 4.04
exim exim 4.33
exim exim 4.52
exim exim 4.62
exim exim 4.34
exim exim 4.65
exim exim 4.61
exim exim 4.30
exim exim 4.24
exim exim 4.50
exim exim 4.74
exim exim 4.71
exim exim 4.42
exim exim 4.75
exim exim 4.32
exim exim 4.31
exim exim 4.64
exim exim 4.05
exim exim 4.21
exim exim 4.22
exim exim 4.51
exim exim 4.44
exim exim 4.76
exim exim 4.41
exim exim 4.80.1
CVE-2016-1531 MEDIUM

Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
exim exim *
CVE-2016-9963 LOW

Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.

CVSS 2.0

Severity: LOW

Problem Type: CWE-320,

Products Affected

Vendor Product Version
canonical ubuntu_linux 16.10
debian debian_linux 8.0
canonical ubuntu_linux 16.04
exim exim *
canonical ubuntu_linux 14.04
canonical ubuntu_linux 12.04
CVE-2017-1000369 LOW

Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note that at this time upstream has released a patch (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21), but it is not known if a new point release is available that addresses this issue at this time.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 4.0 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 2.5 1.4

CVSS 2.0

Severity: LOW

Problem Type: CWE-404,

Products Affected

Vendor Product Version
debian debian_linux 9.0
debian debian_linux 8.0
exim exim 4.89
exim exim *
exim exim 4.88
CVE-2017-16943 HIGH

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-416,

Products Affected

Vendor Product Version
debian debian_linux 9.0
exim exim 4.89
exim exim 4.88
CVE-2017-16944 MEDIUM

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifying the end of the content, related to the bdat_getc function.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-835,

Products Affected

Vendor Product Version
debian debian_linux 9.0
exim exim 4.89
exim exim 4.88
CVE-2018-6789 HIGH

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-120,CWE-120,

Products Affected

Vendor Product Version
debian debian_linux 9.0
debian debian_linux 8.0
canonical ubuntu_linux 16.04
exim exim *
canonical ubuntu_linux 17.10
canonical ubuntu_linux 14.04
debian debian_linux 7.0
CVE-2019-10149 HIGH

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,CWE-78,

Products Affected

Vendor Product Version
debian debian_linux 9.0
canonical ubuntu_linux 18.10
exim exim *
canonical ubuntu_linux 18.04
CVE-2019-13917 HIGH

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

CVSS 2.0

Severity: HIGH

Problem Type: CWE-19,

Products Affected

Vendor Product Version
debian debian_linux 9.0
exim exim *
debian debian_linux 10.0
CVE-2019-15846 HIGH

Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
debian debian_linux 9.0
debian debian_linux 8.0
exim exim *
debian debian_linux 10.0
CVE-2019-16928 HIGH

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,CWE-787,

Products Affected

Vendor Product Version
fedoraproject fedora 30
exim exim *
canonical ubuntu_linux 19.04
fedoraproject fedora 31
debian debian_linux 10.0
fedoraproject fedora 29
CVE-2020-12783 MEDIUM

Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-125,

Products Affected

Vendor Product Version
debian debian_linux 9.0
debian debian_linux 8.0
fedoraproject fedora 32
canonical ubuntu_linux 16.04
exim exim *
canonical ubuntu_linux 19.10
canonical ubuntu_linux 18.04
fedoraproject fedora 31
canonical ubuntu_linux 14.04
canonical ubuntu_linux 20.04
debian debian_linux 10.0
CVE-2020-28007 HIGH

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-59,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28008 HIGH

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), an attacker can write to a /var/spool/exim4/input spool header file, in which a crafted recipient address can indirectly lead to command execution.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-269,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28009 HIGH

Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are accompanied by unbounded increases in a certain size variable. NOTE: exploitation may be impractical because of the execution time needed to overflow (multiple days).

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-190,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28010 HIGH

Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working directory pathname into a buffer that is too small (on some common platforms).

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28011 HIGH

Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause privilege escalation from exim to root.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28012 HIGH

Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privileged pipe that lacks a close-on-exec flag.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28013 HIGH

Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation from any user to root. This occurs because of the interpretation of negative sizes in strncpy.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28014 MEDIUM

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and allows a denial of service because root-owned files can be overwritten.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H 1.8 4.2

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-269,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28015 HIGH

Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processes because a recipient address can have a newline character.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28016 HIGH

Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28017 HIGH

Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-190,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28018 HIGH

Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-416,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28019 MEDIUM

Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-665,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28020 HIGH

Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging the mishandling of continuation lines during header-length restriction.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-190,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28021 HIGH

Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. An authenticated remote SMTP client can insert newline characters into a spool file (which indirectly leads to remote code execution as root) via AUTH= in a MAIL FROM command.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28022 HIGH

Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when processing name=value pairs within MAIL FROM and RCPT TO commands.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28023 MEDIUM

Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to an unauthenticated SMTP client.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-125,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28024 HIGH

Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp_ungetc was only intended to push back characters, but can actually push back non-character error codes such as EOF.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28025 MEDIUM

Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between sig->bodyhash.len and b->bh.len; thus, a crafted DKIM-Signature header might lead to a leak of sensitive information from process memory.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-125,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-28026 HIGH

Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote attackers to execute arbitrary commands as root.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
exim exim *
CVE-2020-8015 HIGH

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: openSUSE Factory exim versions prior to 4.93.0.4-3.1.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9
meissner@suse.de 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 2.5 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-59,CWE-59,

Products Affected

Vendor Product Version
exim exim *
CVE-2021-27216 MEDIUM

Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.3 MEDIUM CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H 1.0 5.2

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
exim exim *
CVE-2021-38371 MEDIUM

The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-74,

Products Affected

Vendor Product Version
exim exim *
CVE-2022-3559

A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.

Products Affected

Vendor Product Version
exim exim *
fedoraproject fedora 35
fedoraproject fedora 36
exim exim -
fedoraproject fedora 37
CVE-2022-3620

A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The name of the patch is 12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211919.

Products Affected

Vendor Product Version
exim exim 2022-10-18
exim exim *
fedoraproject fedora 35
fedoraproject fedora 36
fedoraproject fedora 37
CVE-2022-37451

Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
exim exim *
fedoraproject fedora 35
fedoraproject fedora 36
CVE-2022-37452

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

Products Affected

Vendor Product Version
exim exim *
debian debian_linux 10.0
CVE-2023-42114

Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to disclose information in the context of the service account. . Was ZDI-CAN-17433.

Products Affected

Vendor Product Version
exim exim *
CVE-2023-42115

Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17434.

Products Affected

Vendor Product Version
exim exim *
CVE-2023-42116

Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17515.

Products Affected

Vendor Product Version
exim exim *
CVE-2023-42117

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17554.

Products Affected

Vendor Product Version
exim exim *
CVE-2023-42119

Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. . Was ZDI-CAN-17643.

Products Affected

Vendor Product Version
exim exim *
CVE-2023-51766

Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 3.9 1.4

Products Affected

Vendor Product Version
exim exim *
fedoraproject extra_packages_for_enterprise_linux 8.0
fedoraproject fedora 38
fedoraproject extra_packages_for_enterprise_linux 9.0
fedoraproject extra_packages_for_enterprise_linux 7.0
debian debian_linux 10.0
fedoraproject fedora 39
CVE-2024-39929

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

Products Affected

Vendor Product Version
exim exim *
CVE-2025-26794

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
exim exim *
CVE-2025-30232

A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9
cve@mitre.org 8.1 HIGH CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H 1.4 6.0

Products Affected

Vendor Product Version
exim exim *
CVE-2025-67896

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 6.4 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L 1.6 4.7

Products Affected

Vendor Product Version
exim exim *