CVE-2014-2957
Last modified
CVE-2014-2957 is a vulnerability of currently unknown severity. The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.. EPSS estimates a 5.26% chance of exploitation in the next 30 days.
Description
The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Exim | Exim | <= 4.82 |
| Exim | Exim | 4.00 |
| Exim | Exim | 4.01 |
| Exim | Exim | 4.02 |
| Exim | Exim | 4.03 |
| Exim | Exim | 4.04 |
| Exim | Exim | 4.05 |
| Exim | Exim | 4.10 |
| Exim | Exim | 4.11 |
| Exim | Exim | 4.12 |
| Exim | Exim | 4.14 |
| Exim | Exim | 4.20 |
| Exim | Exim | 4.21 |
| Exim | Exim | 4.22 |
| Exim | Exim | 4.23 |
| Exim | Exim | 4.24 |
| Exim | Exim | 4.30 |
| Exim | Exim | 4.31 |
| Exim | Exim | 4.32 |
| Exim | Exim | 4.33 |
| Exim | Exim | 4.34 |
| Exim | Exim | 4.40 |
| Exim | Exim | 4.41 |
| Exim | Exim | 4.42 |
| Exim | Exim | 4.43 |
| Exim | Exim | 4.44 |
| Exim | Exim | 4.50 |
| Exim | Exim | 4.51 |
| Exim | Exim | 4.52 |
| Exim | Exim | 4.53 |
| Exim | Exim | 4.54 |
| Exim | Exim | 4.60 |
| Exim | Exim | 4.61 |
| Exim | Exim | 4.62 |
| Exim | Exim | 4.63 |
| Exim | Exim | 4.64 |
| Exim | Exim | 4.65 |
| Exim | Exim | 4.66 |
| Exim | Exim | 4.67 |
| Exim | Exim | 4.68 |
| Exim | Exim | 4.69 |
| Exim | Exim | 4.70 |
| Exim | Exim | 4.71 |
| Exim | Exim | 4.72 |
| Exim | Exim | 4.73 |
| Exim | Exim | 4.74 |
| Exim | Exim | 4.75 |
| Exim | Exim | 4.76 |
| Exim | Exim | 4.77 |
| Exim | Exim | 4.80 |
Showing 50 of 51 affected configurations. See NVD for the full list.
References
- https://lists.exim.org/lurker/message/20140528.122536.a31d60a4.en.htmlPatch, Vendor Advisory
- https://lists.exim.org/lurker/message/20140528.122536.a31d60a4.en.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-2957?
How severe is CVE-2014-2957?
How do I fix CVE-2014-2957?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-2948SQL injection vulnerability in workflowenginesoa.asmx in Biz…
- CVE-2014-2949SQL injection vulnerability in the web service in F5 ARX Dat…
- CVE-2014-2950Datum Systems SnIP on PSM-500 and PSM-4500 devices does not …
- CVE-2014-2951Datum Systems SnIP on PSM-500 and PSM-4500 devices has a har…
- CVE-2014-2955Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote…
- CVE-2014-2956ScriptHelperApi in the AVG ScriptHelper ActiveX control in S…
- CVE-2014-2959logViewer.htm on the Dell ML6000 tape backup system with fir…
- CVE-2014-2960Vision Critical before 2014-05-30 allows attackers to read a…
- CVE-2014-2962Absolute path traversal vulnerability in the webproc cgi mod…
- CVE-2014-2963Multiple cross-site scripting (XSS) vulnerabilities in group…
- CVE-2014-2964Cobham Aviator 700D and 700E satellite terminals have hardco…
- CVE-2014-2965Cross-site scripting (XSS) vulnerability in auth-settings-x.…
Are you affected by CVE-2014-2957?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
