CVE-2012-5671
Last modified
CVE-2012-5671 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.. EPSS estimates a 8.38% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Exim | Exim | 4.70 |
| Exim | Exim | 4.71 |
| Exim | Exim | 4.72 |
| Exim | Exim | 4.73 |
| Exim | Exim | 4.74 |
| Exim | Exim | 4.75 |
| Exim | Exim | 4.76 |
| Exim | Exim | 4.77 |
| Exim | Exim | 4.80 |
References
- http://secunia.com/advisories/51098Vendor Advisory
- http://secunia.com/advisories/51098Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-5671?
How severe is CVE-2012-5671?
How do I fix CVE-2012-5671?
Are you affected by CVE-2012-5671?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
