Back

CRITICAL KEV

exim: remote code execution flaw

Published Dec 14, 2010 ·Due Apr 15, 2022

Description

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 14, 2010
Updated Oct 22, 2025
Reserved Nov 30, 2010
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Dec 7, 2010