CVE-2010-4344
Last modified
CVE-2010-4344 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.. CISA has confirmed active exploitation in the wild. EPSS estimates a 71.79% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Exim | Exim | < 4.70 |
| Opensuse | Opensuse | 11.1 |
| Opensuse | Opensuse | 11.2 |
| Opensuse | Opensuse | 11.3 |
| Debian | Debian Linux | 5.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 8.04 |
| Canonical | Ubuntu Linux | 9.10 |
References
- https://bugs.exim.org/show_bug.cgi?id=787Issue Tracking, Patch
- https://lists.exim.org/lurker/message/20101210.164935.385e04d0.en.htmlMailing List, Patch
- https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00003.htmlMailing List, Third Party Advisory
- https://openwall.com/lists/oss-security/2010/12/10/1Mailing List, Third Party Advisory
- https://secunia.com/advisories/40019Broken Link, Vendor Advisory
- https://secunia.com/advisories/42576Broken Link, Vendor Advisory
- https://secunia.com/advisories/42586Broken Link, Vendor Advisory
- https://secunia.com/advisories/42587Broken Link, Vendor Advisory
- https://secunia.com/advisories/42589Broken Link, Vendor Advisory
- https://www.debian.org/security/2010/dsa-2131Mailing List, Third Party Advisory
- https://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.htmlExploit, Mailing List
- https://www.kb.cert.org/vuls/id/682457Third Party Advisory, US Government Resource
- https://www.metasploit.com/modules/exploit/unix/smtp/exim4_string_formatThird Party Advisory
- https://www.openwall.com/lists/oss-security/2021/05/04/7Exploit, Mailing List
- https://www.osvdb.org/69685Broken Link, Exploit, Patch
- https://www.securityfocus.com/archive/1/515172/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/45308Broken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id?1024858Broken Link, Third Party Advisory, VDB Entry
- https://www.theregister.co.uk/2010/12/11/exim_code_execution_peril/Press/Media Coverage
- https://www.ubuntu.com/usn/USN-1032-1Third Party Advisory
- https://www.vupen.com/english/advisories/2010/3171Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3172Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3181Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3186Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3204Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3246Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=661756Exploit, Issue Tracking
- https://bugs.exim.org/show_bug.cgi?id=787Issue Tracking, Patch
- https://lists.exim.org/lurker/message/20101210.164935.385e04d0.en.htmlMailing List, Patch
- https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00003.htmlMailing List, Third Party Advisory
- https://openwall.com/lists/oss-security/2010/12/10/1Mailing List, Third Party Advisory
- https://secunia.com/advisories/40019Broken Link, Vendor Advisory
- https://secunia.com/advisories/42576Broken Link, Vendor Advisory
- https://secunia.com/advisories/42586Broken Link, Vendor Advisory
- https://secunia.com/advisories/42587Broken Link, Vendor Advisory
- https://secunia.com/advisories/42589Broken Link, Vendor Advisory
- https://www.debian.org/security/2010/dsa-2131Mailing List, Third Party Advisory
- https://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.htmlExploit, Mailing List
- https://www.kb.cert.org/vuls/id/682457Third Party Advisory, US Government Resource
- https://www.metasploit.com/modules/exploit/unix/smtp/exim4_string_formatThird Party Advisory
- https://www.openwall.com/lists/oss-security/2021/05/04/7Exploit, Mailing List
- https://www.osvdb.org/69685Broken Link, Exploit, Patch
- https://www.securityfocus.com/archive/1/515172/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/45308Broken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id?1024858Broken Link, Third Party Advisory, VDB Entry
- https://www.theregister.co.uk/2010/12/11/exim_code_execution_peril/Press/Media Coverage
- https://www.ubuntu.com/usn/USN-1032-1Third Party Advisory
- https://www.vupen.com/english/advisories/2010/3171Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3172Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3181Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3186Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3204Broken Link, Vendor Advisory
- https://www.vupen.com/english/advisories/2010/3246Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=661756Exploit, Issue Tracking
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-4344US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2010-4344?
How severe is CVE-2010-4344?
How do I fix CVE-2010-4344?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-4338ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to m…
- CVE-2010-4339Cross-site scripting (XSS) vulnerability in Hypermail 2.2.0 …
- CVE-2010-4340libcloud before 0.4.1 does not verify SSL certificates for H…
- CVE-2010-4341The pam_parse_in_data_v2 function in src/responder/pam/pamsr…
- CVE-2010-4342The aun_incoming function in net/econet/af_econet.c in the L…
- CVE-2010-4343drivers/scsi/bfa/bfa_core.c in the Linux kernel before 2.6.3…5.5
- CVE-2010-4345Exim 4.72 and earlier allows local users to gain privileges …7.8
- CVE-2010-4346The install_special_mapping function in mm/mmap.c in the Lin…
- CVE-2010-4347The ACPI subsystem in the Linux kernel before 2.6.36.2 uses …
- CVE-2010-4348Cross-site scripting (XSS) vulnerability in admin/upgrade_un…
- CVE-2010-4349admin/upgrade_unattended.php in MantisBT before 1.2.4 allows…
- CVE-2010-4350Directory traversal vulnerability in admin/upgrade_unattende…
Are you affected by CVE-2010-4344?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
