CVE-2017-16943
CRITICALExim 4.88-4.89 - Remote Code Execution via BDAT Command Use-After-Free
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-16943. PoCs published by beraphin.
AI-analyzed exploit summary This repository provides a detailed analysis of CVE-2017-16943, a use-after-free (UAF) vulnerability in Exim's receive_msg function. It includes environment setup instructions, vulnerability analysis, and a step-by-step explanation of how the UAF can be triggered to achieve RIP hijacking.
Description
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.
Exploits (1)
This repository provides a detailed analysis of CVE-2017-16943, a use-after-free (UAF) vulnerability in Exim's receive_msg function. It includes environment setup instructions, vulnerability analysis, and a step-by-step explanation of how the UAF can be triggered to achieve RIP hijacking.
References (11)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H