CVE-2010-4344
14.12.2010, 16:00
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.Enginsight
Vendor | Product | Version |
---|---|---|
exim | exim | 𝑥 < 4.70 |
opensuse | opensuse | 11.1 |
opensuse | opensuse | 11.2 |
opensuse | opensuse | 11.3 |
debian | debian_linux | 5.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 9.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References