All errata/sisyphus/ALT-PU-2014-1684-1
ALT-PU-2014-1684-1

Package update exim in branch sisyphus

Version4.82-alt1
Published2014-05-24
Max severityMEDIUM
Severity:

Closed issues (1)

CVE-2012-5671
MEDIUM6.8

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.

Published: 2012-10-31Modified: 2026-04-29
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
References