漏洞描述
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.securityfocus.comhttp://www.securityfocus.com/bid/103049↗git.exim.orghttps://git.exim.org/exim.git/commit/cf3cd306062a08969c41a1cdd32c6855f1abecf1↗packetstormsecurity.comhttp://packetstormsecurity.com/files/162959/Exim-base64d-Buffer-Overflow.html↗www.securitytracker.comhttp://www.securitytracker.com/id/1040461↗lists.debian.orghttps://lists.debian.org/debian-lts-announce/2018/02/msg00009.html↗openwall.comhttp://openwall.com/lists/oss-security/2018/02/10/2↗exim.orghttps://exim.org/static/doc/security/CVE-2018-6789.txt↗usn.ubuntu.comhttps://usn.ubuntu.com/3565-1/↗www.debian.orghttps://www.debian.org/security/2018/dsa-4110↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2018/02/07/2↗