2014-11-05
ALT-BU-2014-3086-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Published: 2014-09-04
Modified: 2025-04-12
Modified: 2025-04-12
CVE-2014-2957
The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.
Severity: MEDIUM (6.8)
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
References:
- http://git.exim.org/exim.git/commitdiff/5b7a7c051c9ab9ee7c924a611f90ef2be03e0ad0
- http://www.openwall.com/lists/oss-security/2021/05/04/7
- https://lists.exim.org/lurker/message/20140528.122536.a31d60a4.en.html
- http://git.exim.org/exim.git/commitdiff/5b7a7c051c9ab9ee7c924a611f90ef2be03e0ad0
- http://www.openwall.com/lists/oss-security/2021/05/04/7
- https://lists.exim.org/lurker/message/20140528.122536.a31d60a4.en.html
Published: 2014-09-04
Modified: 2025-04-12
Modified: 2025-04-12
CVE-2014-2972
expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.
Severity: MEDIUM (4.6)
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P
References:
- http://git.exim.org/exim.git/commitdiff/7685ce68148a083d7759e78d01aa5198fc099c44
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136251.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136264.html
- http://www.ubuntu.com/usn/USN-2933-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1122552
- https://lists.exim.org/lurker/message/20140722.145949.42c043f5.en.html
- https://lists.exim.org/lurker/message/20140722.152452.d6c019e8.en.html
- https://security.gentoo.org/glsa/201607-12
- http://git.exim.org/exim.git/commitdiff/7685ce68148a083d7759e78d01aa5198fc099c44
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136251.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136264.html
- http://www.ubuntu.com/usn/USN-2933-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1122552
- https://lists.exim.org/lurker/message/20140722.145949.42c043f5.en.html
- https://lists.exim.org/lurker/message/20140722.152452.d6c019e8.en.html
- https://security.gentoo.org/glsa/201607-12