CVE-2017-16944: High severity Exim Exim vulnerability
The receivemsg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifying the end of the content, related to the bdatgetc function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-16944?
CVE-2017-16944 is a vulnerability in the SMTP daemon in Exim 4.88 and 4.89 that allows remote attackers to cause a denial of service via vectors involving BDAT commands and an improper check for a '.' character signifying the end of the content.
What is the severity of CVE-2017-16944?
CVE-2017-16944 has a severity of 7.5 (high).
Which versions of Exim are affected by CVE-2017-16944?
Exim versions 4.88 and 4.89 are affected by CVE-2017-16944.
How can CVE-2017-16944 be exploited?
CVE-2017-16944 can be exploited by remote attackers using vectors involving BDAT commands and an improper check for a '.' character.
Where can I find more information about CVE-2017-16944?
More information about CVE-2017-16944 can be found at the following references: [Link 1](https://bugs.exim.org/show_bug.cgi?id=2201), [Link 2](https://lists.exim.org/lurker/message/20171125.034842.d1d75cac.en.html), [Link 3](https://security-tracker.debian.org/tracker/CVE-2017-16944).