CVE-2005-0021

University OF Cambridge Exim < 4.40 - Buffer Overflow

Title source: rule

Description

Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Plugger · clocallinux
https://www.exploit-db.com/exploits/1009
exploitdb WORKING POC VERIFIED
by Rafael Carrasco · clocallinux
https://www.exploit-db.com/exploits/756

Scores

EPSS 0.0282
EPSS Percentile 86.2%

Details

Status published
Products (3)
university_of_cambridge/exim 4.41
university_of_cambridge/exim 4.42
university_of_cambridge/exim < 4.40
Published May 02, 2005
Tracked Since Feb 18, 2026