First published: Wed Jul 31 2024(Updated: )
Phillip Szelat discovered that Exim misparses multiline MIME header filenames. A remote attacker could use this issue to bypass a MIME filename extension-blocking protection mechanism and possibly deliver executable attachments to the mailboxes of end users.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/exim4 | <4.97-4ubuntu4.1 | 4.97-4ubuntu4.1 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/exim4-base | <4.97-4ubuntu4.1 | 4.97-4ubuntu4.1 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/eximon4 | <4.97-4ubuntu4.1 | 4.97-4ubuntu4.1 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/exim4 | <4.95-4ubuntu2.6 | 4.95-4ubuntu2.6 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/exim4-base | <4.95-4ubuntu2.6 | 4.95-4ubuntu2.6 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/eximon4 | <4.95-4ubuntu2.6 | 4.95-4ubuntu2.6 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/exim4 | <4.93-13ubuntu1.12 | 4.93-13ubuntu1.12 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/exim4-base | <4.93-13ubuntu1.12 | 4.93-13ubuntu1.12 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/eximon4 | <4.93-13ubuntu1.12 | 4.93-13ubuntu1.12 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/exim4 | <4.90.1-1ubuntu1.10+esm5 | 4.90.1-1ubuntu1.10+esm5 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/exim4-base | <4.90.1-1ubuntu1.10+esm5 | 4.90.1-1ubuntu1.10+esm5 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/eximon4 | <4.90.1-1ubuntu1.10+esm5 | 4.90.1-1ubuntu1.10+esm5 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/exim4 | <4.86.2-2ubuntu2.6+esm8 | 4.86.2-2ubuntu2.6+esm8 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/exim4-base | <4.86.2-2ubuntu2.6+esm8 | 4.86.2-2ubuntu2.6+esm8 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/eximon4 | <4.86.2-2ubuntu2.6+esm8 | 4.86.2-2ubuntu2.6+esm8 |
Ubuntu Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.