exim: buffer overflow in b64decode() function, possibly leading to remote code execution
Published Feb 8, 2018 ·Due May 3, 2022
9.8
CRITICALCVSS 3.1
EPSS 82.14%
Description
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
Affected products
No data.
Configuration 2
- 7.0
- 8.0
- 9.0
Configuration 3
- 14.04
- 16.04
- 17.10
No data.
Red Hat Enterprise Linux 5
exim
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | exim | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of Exim as shipped in Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is already in the Extended Life Phase of its life cycle and Exim is not on the list of components supported via Red Hat Enterprise Linux 5 Extended Life-cycle Support (ELS) add-on, therefore there's currently no plan to address this issue in Red Hat Enterprise Linux 5. For more information about Red Hat Enterprise Linux 5 life cycle and ELS add-on scope of support, see: https://access.redhat.com/support/policy/updates/errata/#Extended_Life_Cycle_Phase https://access.redhat.com/articles/2901071 The Exim mail server is not shipped in Red Hat Enterprise Linux 6 and 7.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
Date Added
Nov 3, 2021
Patch Due
May 3, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (48 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 82.14% (0.82137) | 99.65th | v5 (v2026.06.15) |
| Jun 15, 2026 | 82.44% (0.82437) | 99.62th | v5 (v2026.06.15) |
| Nov 21, 2025 | 86.44% (0.86439) | 99.37th | v4 (v2025.03.14) |
| Nov 18, 2025 | 73.20% (0.73200) | 98.86th | v4 (v2025.03.14) |
| Nov 8, 2025 | 87.11% (0.87108) | 99.40th | v4 (v2025.03.14) |
| Oct 23, 2025 | 85.06% (0.85059) | 99.30th | v4 (v2025.03.14) |
| Oct 17, 2025 | 86.79% (0.86790) | 99.39th | v4 (v2025.03.14) |
| Jun 15, 2025 | 84.45% (0.84455) | 99.26th | v4 (v2025.03.14) |
| Jun 4, 2025 | 72.08% (0.72078) | 98.65th | v4 (v2025.03.14) |
| Jun 1, 2025 | 74.97% (0.74972) | 98.80th | v4 (v2025.03.14) |
| May 4, 2025 | 72.08% (0.72078) | 98.65th | v4 (v2025.03.14) |
| May 1, 2025 | 74.97% (0.74972) | 98.80th | v4 (v2025.03.14) |
| Apr 29, 2025 | 72.08% (0.72078) | 98.64th | v4 (v2025.03.14) |
| Apr 1, 2025 | 74.46% (0.74459) | 98.77th | v4 (v2025.03.14) |
| Mar 31, 2025 | 77.09% (0.77091) | 98.91th | v4 (v2025.03.14) |
| Mar 30, 2025 | 74.46% (0.74459) | 98.77th | v4 (v2025.03.14) |
| Mar 29, 2025 | 88.88% (0.88879) | 99.42th | v4 (v2025.03.14) |
| Mar 28, 2025 | 74.46% (0.74459) | 98.77th | v4 (v2025.03.14) |
| Mar 27, 2025 | 85.57% (0.85573) | 99.31th | v4 (v2025.03.14) |
| Mar 24, 2025 | 83.03% (0.83032) | 99.23th | v4 (v2025.03.14) |
| Mar 23, 2025 | 85.64% (0.85640) | 99.33th | v4 (v2025.03.14) |
| Mar 20, 2025 | 83.03% (0.83032) | 99.24th | v4 (v2025.03.14) |
| Mar 19, 2025 | 85.74% (0.85744) | 99.34th | v4 (v2025.03.14) |
| Mar 17, 2025 | 83.03% (0.83032) | 99.21th | v4 (v2025.03.14) |
| Dec 17, 2024 | 94.06% (0.94064) | 99.37th | v3 (v2023.03.01) |
| Dec 12, 2024 | 95.81% (0.95806) | 99.52th | v3 (v2023.03.01) |
| Jun 25, 2024 | 96.79% (0.96791) | 99.69th | v3 (v2023.03.01) |
| May 14, 2024 | 96.83% (0.96827) | 99.69th | v3 (v2023.03.01) |
| Feb 24, 2024 | 96.76% (0.96761) | 99.64th | v3 (v2023.03.01) |
| Jan 19, 2024 | 96.86% (0.96862) | 99.64th | v3 (v2023.03.01) |
| Dec 19, 2023 | 97.12% (0.97117) | 99.74th | v3 (v2023.03.01) |
| Nov 24, 2023 | 97.22% (0.97223) | 99.79th | v3 (v2023.03.01) |
| Aug 11, 2023 | 97.26% (0.97257) | 99.76th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.30% (0.97299) | 99.78th | v3 (v2023.03.01) |
| Jul 2, 2023 | 97.36% (0.97357) | 99.83th | v3 (v2023.03.01) |
| Jun 10, 2023 | 97.34% (0.97343) | 99.82th | v3 (v2023.03.01) |
| May 3, 2023 | 97.33% (0.97334) | 99.79th | v3 (v2023.03.01) |
| Apr 15, 2023 | 97.39% (0.97394) | 99.84th | v3 (v2023.03.01) |
| Mar 28, 2023 | 97.39% (0.97388) | 99.83th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.48% (0.97477) | 99.94th | v3 (v2023.03.01) |
| Mar 6, 2023 | 49.85% (0.49849) | 98.72th | v2 (v2022.01.01) |
| Apr 17, 2022 | 49.85% (0.49849) | 98.56th | v2 (v2022.01.01) |
| Feb 4, 2022 | 53.46% (0.53465) | 98.38th | v2 (v2022.01.01) |
| Feb 3, 2022 | 18.99% (0.18991) | 93.68th | v1 |
| Jan 6, 2022 | 18.99% (0.18991) | 93.61th | v1 |
| Sep 1, 2021 | 18.99% (0.18991) | 97.83th | v1 |
| Jun 4, 2021 | 18.99% (0.18991) | 0.00th | v1 |
| Apr 14, 2021 | 17.87% (0.17870) | 0.00th | v1 |
References (19)
- http://openwall.com/lists/oss-security/2018/02/10/2 x_refsource_CONFIRMMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/162959/Exim-base64d-Buffer-Overflow.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2018/02/07/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/103049 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040461 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-6789 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1543268 Issue Tracking
- https://devco.re/blog/2018/03/06/exim-off-by-one-RCE-exploiting-CVE-2018-6789-en/ x_refsource_MISCExploitThird Party Advisory
- https://exim.org/static/doc/security/CVE-2018-6789.txt x_refsource_CONFIRMVendor Advisory
- https://git.exim.org/exim.git/commit/cf3cd306062a08969c41a1cdd32c6855f1abecf1 x_refsource_CONFIRMPatch
- https://lists.debian.org/debian-lts-announce/2018/02/msg00009.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-6789
- https://usn.ubuntu.com/3565-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-6789 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2018-6789
- https://www.debian.org/security/2018/dsa-4110 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
- https://www.exploit-db.com/exploits/44571/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/45671/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.