CVE-2017-16944
HIGHExim 4.88-4.89 - DoS
Title source: llmDescription
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifying the end of the content, related to the bdat_getc function.
Exploits (1)
References (9)
Scores
CVSS v3
7.5
EPSS
0.7603
EPSS Percentile
98.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-835
Status
published
Products (3)
debian/debian_linux
9.0
exim/exim
4.88
exim/exim
4.89
Published
Nov 25, 2017
Tracked Since
Feb 18, 2026