Home page logo

oss-sec logo oss-sec mailing list archives

CVE-2011-1764 Exim: DKIM Format String
From: Djalal Harouni <tixxdz () opendz org>
Date: Fri, 15 Jul 2011 11:49:27 +0100

A format string vulnerability affects the Exim SMTP server with DomainKeys
Identified Mail (DKIM) support, version between 4.70 and 4.75. The DKIM
logging mechanism did not use format string specifiers when logging some
parts of the DKIM-Signature header field. A remote attacker who is able
to send emails, can exploit this vulnerability and execute arbitrary
code with the privileges of the Exim daemon [1].

MITRE assigned CVE-2011-1764 to this vulnerability but the entry was not
updated [2]. We would appreciate if it can be updated, we are using this
CVE name in one of our new Nmap scripts smtp-vuln-cve2011-1764.nse [3].


[1] http://thread.gmane.org/gmane.mail.exim.devel/4946
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-1764
[3] http://seclists.org/nmap-dev/2011/q3/221


  By Date           By Thread  

Current thread:
  • CVE-2011-1764 Exim: DKIM Format String Djalal Harouni (Jul 15)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]