Information disclosure in Exim - CVE-2016-9963
Published: December 19, 2016 / Updated: January 5, 2017
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to usage of incorrect buffer when displaying error message for DATA command in src/src/transports/smtp.c file. A remote unauthenticated attacker can send a specially crafted SMTP command and obtain potentially sensitive information, such as DKIM key.
Affected software
Amazon Linux AMI
Fedora
Ubuntu
Opensuse
exim