CVE-2022-3620
Last modified
CVE-2022-3620 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The name of the patch is 12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211919.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Exim | Exim | >= 4.95, < 4.97 |
| Fedoraproject | Fedora | 35 |
| Fedoraproject | Fedora | 36 |
| Fedoraproject | Fedora | 37 |
References
- https://git.exim.org/exim.git/commit/12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445Mailing List, Patch, Vendor Advisory
- https://vuldb.com/?id.211919Third Party Advisory
- https://git.exim.org/exim.git/commit/12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445Mailing List, Patch, Vendor Advisory
- https://vuldb.com/?id.211919Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-3620?
How severe is CVE-2022-3620?
How do I fix CVE-2022-3620?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36190GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free v…9.8
- CVE-2022-36191A heap-buffer-overflow had occurred in function gf_isom_dovi…5.5
- CVE-2022-36193SQL injection in School Management System 1.0 allows remote …9.8
- CVE-2022-36194Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS)…5.4
- CVE-2022-36197BigTree CMS 4.4.16 was discovered to contain an arbitrary fi…5.4
- CVE-2022-36198Multiple SQL injections detected in Bus Pass Management Syst…9.8
- CVE-2022-36200In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin…7.5
- CVE-2022-36201Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi…9.8
- CVE-2022-36202Doctor's Appointment System1.0 is vulnerable to Incorrect Ac…9.8
- CVE-2022-36203Doctor's Appointment System 1.0 is vulnerable to Cross Site …6.1
- CVE-2022-3621A vulnerability was found in Linux Kernel. It has been class…6.5
- CVE-2022-36215DedeBIZ v6 was discovered to contain a remote code execution…7.2
Are you affected by CVE-2022-3620?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
