exim4: format string vulnerability
| Package(s): | exim4 |
CVE #(s): | CVE-2011-1764
|
| Created: | May 9, 2011 |
Updated: | May 18, 2011 |
| Description: |
From the Exim advisory:
A format string attack in logging DKIM
information from an inbound mail may permit anyone who can send you
email to cause code to be executed as the Exim run-time user. No
exploit is known to exist, but we do not believe that an experienced
attacker would find the exploit hard to construct.
|
| Alerts: |
| Gentoo |
201401-32 |
exim |
2014-01-27 |
| openSUSE |
openSUSE-SU-2012:1404-1 |
exim |
2012-10-27 |
| Debian |
DSA-2232-1 |
exim4 |
2011-05-06 |
| Fedora |
FEDORA-2011-7047 |
exim |
2011-05-17 |
| Fedora |
FEDORA-2011-7059 |
exim |
2011-05-17 |
| SUSE |
SUSE-SR:2011:009 |
mailman, openssl, tgt, rsync, vsftpd, libzip1/libzip-devel, otrs, libtiff, kdelibs4, libwebkit, libpython2_6-1_0, perl, pure-ftpd, collectd, vino, aaa_base, exim |
2011-05-17 |
| Ubuntu |
USN-1130-1 |
exim4 |
2011-05-10 |
| openSUSE |
openSUSE-SU-2011:0456-1 |
exim |
2011-05-09 |
|