CVE-2018-6789: Exim Buffer Overflow Vulnerability
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
Other sources
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/exim4to a version that resolves this vulnerability.Fixed in 4.90.1-1Fixed in 4.89-2+deb9u3Fixed in 4.84.2-2+deb8u5 - Upgrade
Upgrade
debian/exim4to a version that resolves this vulnerability.Fixed in 4.94.2-7+deb11u3Fixed in 4.94.2-7+deb11u6Fixed in 4.96-15+deb12u10Fixed in 4.98.2-1+deb13u3Fixed in 4.98.2-1+deb13u4Fixed in 4.99.4-2 - Upgrade
Upgrade
Eximto a version that resolves this vulnerability.Fixed in 4.90.1
Event History
Frequently Asked Questions
What is CVE-2018-6789?
CVE-2018-6789 is a vulnerability in Exim that can result in a buffer overflow, allowing remote code execution.
What is the severity level of CVE-2018-6789?
The severity level of CVE-2018-6789 is critical, with a CVSS score of 9.8.
What software or versions are affected by CVE-2018-6789?
Exim versions up to and exclusive of 4.90.1, Debian Linux 7.0 to 9.0, and Ubuntu Linux 14.04 to 17.10 are affected by CVE-2018-6789.
How can CVE-2018-6789 be fixed?
To fix CVE-2018-6789, users should update to Exim version 4.90.1 or later, or apply the appropriate patches provided by Debian or Ubuntu.
Where can I find more information about CVE-2018-6789?
More information about CVE-2018-6789 can be found at the Debian Security Tracker, MITRE CVE website, and the Exim website.