Back

LOW

Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability

Published May 3, 2024

Description

Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. . Was ZDI-CAN-17643.

Affected products

Remediation

Red Hat statement

The vulnerable package Exim is not shipped in any Red Hat products.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner zdi
Published May 3, 2024
Updated Nov 3, 2025
Reserved Sep 6, 2023
CISA Vulnrichment
Updated Jul 5, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 27, 2023
ENISA EUVD
Assigner zdi
Published May 3, 2024
Updated Nov 3, 2025
Exploited since n/a
EUVD-2023-46578