[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253390

 
 

909

 
 

197257

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Exim: RCE using a heap-based buffer overflow (CVE-2019-16928)

ID: oval:org.secpod.oval:def:1801622Date: (C)2019-11-27   (M)2023-11-10
Class: PATCHFamily: unix




There is a heap-based buffer overflow in string_vformat . The currently known exploit uses a extraordinary long EHLO string to crash the Exim process that is receiving the message. While at this mode of operation Exim already dropped its privileges, other paths to reach the vulnerable code may exist.

Platform:
Alpine Linux 3.10
Product:
exim
Reference:
10834
CVE-2019-16928
CVE    1
CVE-2019-16928
CPE    2
cpe:/o:alpinelinux:alpine_linux:3.10
cpe:/a:exim:exim

© SecPod Technologies