#VU1432 Information disclosure in Exim - CVE-2016-9963
Published: December 19, 2016 / Updated: January 5, 2017
Exim
Exim
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to usage of incorrect buffer when displaying error message for DATA command in src/src/transports/smtp.c file. A remote unauthenticated attacker can send a specially crafted SMTP command and obtain potentially sensitive information, such as DKIM key.