7.5
CVSSv2

CVE-2011-1407

Published: 16/05/2011 Updated: 07/09/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The DKIM implementation in Exim 4.7x prior to 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote malicious users to execute arbitrary code or access a filesystem via a crafted identity.

Vulnerable Product Search on Vulmon Subscribe to Product

exim exim 4.74

exim exim 4.75

exim exim 4.72

exim exim 4.73

exim exim 4.70

exim exim 4.71

Vendor Advisories

An attacker could send crafted input to Exim and cause it to run programs as the Exim user ...