vendor:
Exim
by:
Unknown
7.5
CVSS
HIGH
Remote Code Execution
Not provided
CWE
Product Name: Exim
Affected Version From: exim-4.41
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Debian GNU/Linux
2005
Proof-of-Concept for Exim Remote Code Execution Vulnerability
This proof-of-concept demonstrates the existence of the vulnerability reported by iDEFENSE (iDEFENSE Security Advisory 01.14.05). It allows an attacker to execute arbitrary code on a vulnerable system. The exploit has been tested against exim-4.41 under Debian GNU/Linux.
Mitigation:
Apply the latest patches for Exim or upgrade to a non-vulnerable version. Regularly update and patch all software components.