[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2017-1000369Date: (C)2017-06-20   (M)2023-12-22


Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note that at this time upstream has released a patch (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21), but it is not known if a new point release is available that addresses this issue at this time.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 4.0CVSS Score : 2.1
Exploit Score: 2.5Exploit Score: 3.9
Impact Score: 1.4Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: NONEAvailability: NONE
Integrity: LOW 
Availability: NONE 
  
Reference:
SECTRACK-1038779
BID-99252
DSA-3888
GLSA-201709-19
https://access.redhat.com/security/cve/CVE-2017-1000369
https://github.com/Exim/exim/commit/65e061b76867a9ea7aeeb535341b790b90ae6c21
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt

CWE    1
CWE-404
OVAL    6
oval:org.secpod.oval:def:1800052
oval:org.secpod.oval:def:1800278
oval:org.secpod.oval:def:602954
oval:org.secpod.oval:def:703662
...

© SecPod Technologies