https://seclists.org/oss-sec/2025/q4/256: EXIM-Security-2025-12-09.1: Exim 4.99: mote heap corruption
Published Dec 10, 2025
·Updated
Affected Software
1 affected component
Exim Exim>4.98.1
Frequently Asked Questions
1
What is the severity of EXIM-Security-2025-12-09.1?
The severity of EXIM-Security-2025-12-09.1 is critical due to the potential for remote code execution through heap corruption.
2
How do I fix EXIM-Security-2025-12-09.1?
To fix EXIM-Security-2025-12-09.1, upgrade to the latest version of Exim, which includes security patches.
3
What software is affected by EXIM-Security-2025-12-09.1?
The affected software is Exim version 4.99.
4
Can an attacker exploit EXIM-Security-2025-12-09.1 remotely?
Yes, a remote, unauthenticated attacker can exploit EXIM-Security-2025-12-09.1 to cause heap corruption.
5
Is it necessary to take immediate action for EXIM-Security-2025-12-09.1?
Yes, it is recommended to take immediate action to mitigate the risks associated with EXIM-Security-2025-12-09.1.