First published: Thu Jul 04 2024(Updated: )
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/exim4 | <4.90.1-1ubuntu1.10+ | 4.90.1-1ubuntu1.10+ |
ubuntu/exim4 | <4.93-13ubuntu1.12 | 4.93-13ubuntu1.12 |
ubuntu/exim4 | <4.95-4ubuntu2.6 | 4.95-4ubuntu2.6 |
ubuntu/exim4 | <4.97-4ubuntu4.1 | 4.97-4ubuntu4.1 |
ubuntu/exim4 | <4.86.2-2ubuntu2.6+ | 4.86.2-2ubuntu2.6+ |
debian/exim4 | <=4.94.2-7+deb11u2<=4.96-15+deb12u4 | 4.94.2-7+deb11u3 4.96-15+deb12u5 4.98-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.