7.5
CVSSv2

CVE-2004-0399

Published: 07/07/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in Exim 3.35, and other versions prior to 4, when the sender_verify option is true, allows remote malicious users to cause a denial of service and possibly execute arbitrary code during sender verification.

Vulnerable Product Search on Vulmon Subscribe to Product

university of cambridge exim 3.35

university of cambridge exim

Vendor Advisories

Georgi Guninski discovered two stack-based buffer overflows in exim and exim-tls They cannot be exploited with the default configuration from the Debian system, though The Common Vulnerabilities and Exposures project identifies the following problems that are fixed with this update: CAN-2004-0399 When "sender_verify = true" is configured in ...
Georgi Guninski discovered two stack-based buffer overflows They can not be exploited with the default configuration from the Debian system, though The Common Vulnerabilities and Exposures project identifies the following problems that are fixed with this update: CAN-2004-0399 When "sender_verify = true" is configured in eximconf a buffer ...

Exploits

source: wwwsecurityfocuscom/bid/10290/info Exim has been reported prone to a remotely exploitable stack-based buffer overrun vulnerability This is exposed if sender verification has been enabled in the agent and may be triggered by a malicious e-mail Exploitation may permit execution of arbitrary code in the content of the mail transf ...