Vulnerabilities
Vulnerable Software
Exim:  >> Exim  >> 4.75  Security Vulnerabilities
Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.
CVSS Score
7.5
EPSS Score
0.027
Published
2011-10-05
The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.
CVSS Score
7.5
EPSS Score
0.007
Published
2011-05-16


Contact Us

Shodan ® - All rights reserved