[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Exim: RCE using a heap-based buffer overflow (CVE-2019-16928)

ID: oval:org.secpod.oval:def:1801622Date: (C)2019-11-27   (M)2023-11-10
Class: PATCHFamily: unix




There is a heap-based buffer overflow in string_vformat . The currently known exploit uses a extraordinary long EHLO string to crash the Exim process that is receiving the message. While at this mode of operation Exim already dropped its privileges, other paths to reach the vulnerable code may exist.

Platform:
Alpine Linux 3.10
Product:
exim
Reference:
10834
CVE-2019-16928
CVE    1
CVE-2019-16928
CPE    2
cpe:/o:alpinelinux:alpine_linux:3.10
cpe:/a:exim:exim

© SecPod Technologies