CVE-2012-5671: Buffer Overflow
Heap-based buffer overflow in the dkimeximquerydnstxt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and aclsmtpconnect and aclsmtprcpt are not set to "warn control = dkimdisableverify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5671?
CVE-2012-5671 has a severity rating that allows remote attackers to execute arbitrary code, indicating a high level of risk.
How do I fix CVE-2012-5671?
To fix CVE-2012-5671, upgrade Exim to a version later than 4.80 where this vulnerability is addressed.
Which versions of Exim are affected by CVE-2012-5671?
CVE-2012-5671 affects Exim versions 4.70 through 4.80.
What is the cause of CVE-2012-5671?
CVE-2012-5671 is caused by a heap-based buffer overflow in the dkim_exim_query_dns_txt function when specific DKIM settings are not configured.
Can CVE-2012-5671 be exploited through email?
Yes, CVE-2012-5671 can be exploited by remote attackers through maliciously crafted email messages.