Back

MEDIUM

exim: remote arbitrary code execution via DMARC code parsing

Published Sep 4, 2014

Description

The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of Exim as shipped with Red Hat Enterprise Linux 5 as they did not include the experimental DMARC support.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Sep 4, 2014
Updated Aug 6, 2024
Reserved Apr 21, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date May 28, 2014