Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-16944

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifying the end of the content, related to the bdat_getc function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.75
EPSS Ranking 98.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
References
Products affected by CVE-2017-16944
  • Exim » Exim » Version: 4.88
    cpe:2.3:a:exim:exim:4.88
  • Exim » Exim » Version: 4.89
    cpe:2.3:a:exim:exim:4.89
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0


Contact Us

Shodan ® - All rights reserved