Description
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
Exploits (2)
nomisec
WORKING POC
5 stars
by michael-david-fry · poc
https://github.com/michael-david-fry/CVE-2024-39929
References (5)
Scores
CVSS v3
5.4
EPSS
0.6031
EPSS Percentile
98.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-116
Status
published
Products (1)
exim/exim
< 4.97.1
Published
Jul 04, 2024
Tracked Since
Feb 18, 2026