Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before...
Vulnerability Description
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2003-0743
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.debian.org/security/2003/dsa-376
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000735
- http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057720.html
- http://www.exim.org/pipermail/exim-announce/2003q3/000094.html
- http://marc.info/?l=bugtraq&m=106252015820395&w=2
- http://marc.info/?l=vuln-dev&m=106264740820334&w=2
- http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057809.html
- http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changelog
- http://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changelog
More from university of cambridge
View All →Affected Vendor
university of cambridge
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.