VulnerabilityAnalyzed
CVE-2010-4344
Exim Heap-Based Buffer Overflow Vulnerability
KEVCRITICAL 9.8EPSS 71.9%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 71.90% probability · 99th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-787
- Affected
- exim/exim · opensuse/opensuse · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-4344
References
- ftp://ftp.exim.org/pub/exim/ChangeLogs/ChangeLog-4.70Broken Link
- http://atmail.com/blog/2010/atmail-6204-now-available/Broken Link
- http://bugs.exim.org/show_bug.cgi?id=787Issue Tracking, Patch
- http://git.exim.org/exim.git/commit/24c929a27415c7cfc7126c47e4cad39acf3efa6bMailing List, Patch
- http://lists.exim.org/lurker/message/20101210.164935.385e04d0.en.htmlMailing List, Patch
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00003.htmlMailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/12/10/1Mailing List, Third Party Advisory
- http://secunia.com/advisories/40019Broken Link, Vendor Advisory
- http://secunia.com/advisories/42576Broken Link, Vendor Advisory
- http://secunia.com/advisories/42586Broken Link, Vendor Advisory
- http://secunia.com/advisories/42587Broken Link, Vendor Advisory
- http://secunia.com/advisories/42589Broken Link, Vendor Advisory
- http://www.cpanel.net/2010/12/exim-remote-memory-corruption-vulnerability-notification-cve-2010-4344.htmlBroken Link
- http://www.debian.org/security/2010/dsa-2131Mailing List, Third Party Advisory
- http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.htmlExploit, Mailing List
- http://www.kb.cert.org/vuls/id/682457Third Party Advisory, US Government Resource
- http://www.metasploit.com/modules/exploit/unix/smtp/exim4_string_formatThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/05/04/7Exploit, Mailing List
- http://www.osvdb.org/69685Broken Link, Exploit, Patch
- http://www.redhat.com/support/errata/RHSA-2010-0970.htmlBroken Link
- http://www.securityfocus.com/archive/1/515172/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/45308Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024858Broken Link, Third Party Advisory, VDB Entry
- http://www.theregister.co.uk/2010/12/11/exim_code_execution_peril/Press/Media Coverage
- http://www.ubuntu.com/usn/USN-1032-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3171Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3172Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3181Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3186Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3204Broken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.