Input validation error in Exim - CVE-2011-1407

 

Input validation error in Exim - CVE-2011-1407

Published: May 16, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45039
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1407
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.


Affected software

Exim
Fedora
exim

How to mitigate CVE-2011-1407

Install update from vendor's website.

exim - addressed in versions 4.72-2.el6, 4.72-4.el6

External References

Related Security Bulletins