vendor:
Exim Mail Client
by:
SecurityFocus
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Exim Mail Client
Affected Version From: 1.62
Affected Version To: 1.62
Patch Exists: YES
Related CWE: N/A
CPE: exim:exim
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2001
Exim Mail Client Version 1.62 Local Root Buffer Overflow Vulnerability
A potential local root yielding buffer overflow vulnerability exists in Exim mail client version 1.62. A buffer used in processing filenames of message attachments can be overflowed by a maliciously-formed filename. As a result, the excessive data copied onto the stack can overwrite critical parts of the stack frame such as the calling functions' return address. If properly exploited, this can yield root privilege to the attacker.
Mitigation:
Upgrade to the latest version of Exim mail client.