CVE-2014-2957
04.09.2014, 17:55
The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.Enginsight
| Vendor | Product | Version |
|---|---|---|
| exim | exim | 𝑥 ≤ 4.82 |
| exim | exim | 4.00 |
| exim | exim | 4.01 |
| exim | exim | 4.02 |
| exim | exim | 4.03 |
| exim | exim | 4.04 |
| exim | exim | 4.05 |
| exim | exim | 4.10 |
| exim | exim | 4.11 |
| exim | exim | 4.12 |
| exim | exim | 4.14 |
| exim | exim | 4.20 |
| exim | exim | 4.21 |
| exim | exim | 4.22 |
| exim | exim | 4.23 |
| exim | exim | 4.24 |
| exim | exim | 4.30 |
| exim | exim | 4.31 |
| exim | exim | 4.32 |
| exim | exim | 4.33 |
| exim | exim | 4.34 |
| exim | exim | 4.40 |
| exim | exim | 4.41 |
| exim | exim | 4.42 |
| exim | exim | 4.43 |
| exim | exim | 4.44 |
| exim | exim | 4.50 |
| exim | exim | 4.51 |
| exim | exim | 4.52 |
| exim | exim | 4.53 |
| exim | exim | 4.54 |
| exim | exim | 4.60 |
| exim | exim | 4.61 |
| exim | exim | 4.62 |
| exim | exim | 4.63 |
| exim | exim | 4.64 |
| exim | exim | 4.65 |
| exim | exim | 4.66 |
| exim | exim | 4.67 |
| exim | exim | 4.68 |
| exim | exim | 4.69 |
| exim | exim | 4.70 |
| exim | exim | 4.71 |
| exim | exim | 4.72 |
| exim | exim | 4.73 |
| exim | exim | 4.74 |
| exim | exim | 4.75 |
| exim | exim | 4.76 |
| exim | exim | 4.77 |
| exim | exim | 4.80 |
| exim | exim | 4.80.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References