4

CVE-2017-1000369

Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note that at this time upstream has released a patch (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21), but it is not known if a new point release is available that addresses this issue at this time.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Exim ≫ Exim Version <= 4.87.1
Exim ≫ Exim Version 4.88 Update -
Exim ≫ Exim Version 4.88 Update rc1
Exim ≫ Exim Version 4.88 Update rc2
Exim ≫ Exim Version 4.88 Update rc3
Exim ≫ Exim Version 4.88 Update rc4
Exim ≫ Exim Version 4.88 Update rc5
Exim ≫ Exim Version 4.88 Update rc6
Exim ≫ Exim Version 4.89 Update -
Exim ≫ Exim Version 4.89 Update rc1
Exim ≫ Exim Version 4.89 Update rc2
Exim ≫ Exim Version 4.89 Update rc3
Exim ≫ Exim Version 4.89 Update rc4
Exim ≫ Exim Version 4.89 Update rc5
Exim ≫ Exim Version 4.89 Update rc6
Exim ≫ Exim Version 4.89 Update rc7
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.407
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 2.5 1.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
CWE-404 Improper Resource Shutdown or Release

The product does not release or incorrectly releases a resource before it is made available for re-use.

https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt
Third Party Advisory
http://www.debian.org/security/2017/dsa-3888
Third Party Advisory
http://www.securityfocus.com/bid/99252
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038779
Third Party Advisory
VDB Entry
https://access.redhat.com/security/cve/CVE-2017-1000369
Vendor Advisory
https://github.com/Exim/exim/commit/65e061b76867a9ea7aeeb535341b790b90ae6c21
Third Party Advisory
Mitigation
https://security.gentoo.org/glsa/201709-19
Third Party Advisory