CVE-2011-1764

UnknownEPSS 3.94%

Last modified

CVE-2011-1764 is a vulnerability of currently unknown severity. Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.. EPSS estimates a 3.94% chance of exploitation in the next 30 days.

Description

Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.

Metrics

EPSS Probability
3.94%

89.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
EximExim<= 4.75
EximExim2.10
EximExim2.11
EximExim2.12
EximExim3.00
EximExim3.01
EximExim3.02
EximExim3.03
EximExim3.10
EximExim3.11
EximExim3.12
EximExim3.13
EximExim3.14
EximExim3.15
EximExim3.16
EximExim3.20
EximExim3.21
EximExim3.22
EximExim3.30
EximExim3.31
EximExim3.32
EximExim3.33
EximExim3.34
EximExim3.35
EximExim3.36
EximExim4.00
EximExim4.01
EximExim4.02
EximExim4.03
EximExim4.04
EximExim4.05
EximExim4.10
EximExim4.11
EximExim4.12
EximExim4.14
EximExim4.20
EximExim4.21
EximExim4.22
EximExim4.23
EximExim4.24
EximExim4.30
EximExim4.31
EximExim4.32
EximExim4.33
EximExim4.34
EximExim4.40
EximExim4.41
EximExim4.42
EximExim4.43
EximExim4.44

Showing 50 of 70 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-1764?
Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.
How severe is CVE-2011-1764?
Severity scoring for CVE-2011-1764 is pending analysis. The EPSS model estimates a 3.94% probability of exploitation in the next 30 days.
How do I fix CVE-2011-1764?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-1764?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST