Back to Database
Status published
High
CVE-2002-1381
Format string vulnerability in daemon.c for Exim 4.x through 4.10,...
Vulnerability Description
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-1381
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10761
- http://www.securityfocus.com/bid/6314
- http://marc.info/?l=bugtraq&m=103903403527788&w=2
- http://marc.info/?l=bugtraq&m=104006219018664&w=2
- http://groups.yahoo.com/group/exim-users/message/42358
- http://www.exim.org/pipermail/exim-users/Week-of-Mon-20021202/046978.html
More from university of cambridge
View All →CVE-2005-0022
Buffer overflow in the spa_base64_to_bits function in Exim before 4.43,...
Medium
4.6
CVE-2005-0021
Multiple buffer overflows in Exim before 4.43 may allow attackers...
High
7.2
CVE-2004-0400
Stack-based buffer overflow in Exim 4 before 4.33, when the...
High
7.5
CVE-2004-0399
Stack-based buffer overflow in Exim 3.35, and other versions before...
High
7.5
CVE-2003-0743
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before...
High
7.5
Affected Vendor
university of cambridge
View all reports →Affected Software
exim
Vulnerable Versions:
3.35, 3.36, 4.10
Timeline
Official Publish:
September 1st, 2004
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.