openwall.com
http://openwall.com/lists/oss-security/2017/11/25/1 CVE-2017-16944
HIGH
Exim 4.89 - 'BDAT' Denial of Service
Record summary
CVE-2017-16944 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifying the end of the content, related to the bdat_getc function.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBExim 4.89 - 'BDAT' Denial of ServiceExploitDB exploitby mehNot analyzed1 file
References
10openwall.com
http://openwall.com/lists/oss-security/2017/11/25/2 openwall.com
http://openwall.com/lists/oss-security/2017/11/25/3 [oss-security] 20210504 21Nails: Multiple vulnerabilities in Eximmailing list
http://www.openwall.com/lists/oss-security/2021/05/04/7 1039873vdb entry
http://www.securitytracker.com/id/1039873 bugs.exim.org
https://bugs.exim.org/show_bug.cgi?id=2201 lists.exim.org
https://lists.exim.org/lurker/message/20171125.034842.d1d75cac.en.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-16944 DSA-4053Vendor advisory
https://www.debian.org/security/2017/dsa-4053 43184exploit
https://www.exploit-db.com/exploits/43184