Multiple buffer overflows in Exim before 4.43 may allow attackers...
Vulnerability Description
Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-0021
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.idefense.com/application/poi/display?id=179&type=vulnerabilities
- http://www.kb.cert.org/vuls/id/132992
- http://www.debian.org/security/2005/dsa-635
- http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44
- http://www.debian.org/security/2005/dsa-637
- http://www.idefense.com/application/poi/display?id=183&type=vulnerabilities
- http://www.redhat.com/support/errata/RHSA-2005-025.html
- http://security.gentoo.org/glsa/glsa-200501-23.xml
- http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10347
More from university of cambridge
View All →Affected Vendor
university of cambridge
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.