5.9
CVSSv3

CVE-2016-9963

Published: 01/02/2017 Updated: 15/02/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

Exim prior to 4.87.1 might allow remote malicious users to obtain the private DKIM signing key via vectors related to log files and bounce messages.

Vulnerable Product Search on Vulmon Subscribe to Product

exim exim

canonical ubuntu linux 16.10

canonical ubuntu linux 12.04

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

debian debian linux 8.0

Vendor Advisories

Exim could be made to expose private DKIM signing keys ...
Bjoern Jacke discovered that Exim, Debian's default mail transfer agent, may leak the private DKIM signing key to the log files if specific configuration options are met For the stable distribution (jessie), this problem has been fixed in version 4842-2+deb8u2 We recommend that you upgrade your exim4 packages ...
It was found that Exim leaked DKIM signing private keys to the "mainlog" log file As a result, an attacker with access to system log files could potentially access these leaked DKIM private keys ...
It was found that Exim leaked DKIM signing private keys to the "mainlog" log file As a result, an attacker with access to system log files could potentially access these leaked DKIM private keys ...

Recent Articles

Bad news: Exim hole was going to be patched on Xmas Day. Good news: Keyword 'was'
The Register • John Leyden • 22 Dec 2016

Code release for info-leak bug brought forward

Updated An information-leaking security hole in widely used email agent Exim – scheduled for repair on Christmas Day – may now be publicly patched earlier, possibly as soon as Friday. System administrators were stunned by the suggestion that a patch for the vulnerability would be released on December 25 when pretty much everyone working in IT will have the day off. An Exim maintainer, Heiko Schlittermann, admitted the timing of the release wasn’t ideal and suggested that holding up the rel...