Vulnerability Name: | CVE-2011-1407 (CCN-67455) | ||||||||||||||||||||||||
Assigned: | 2011-05-12 | ||||||||||||||||||||||||
Published: | 2011-05-12 | ||||||||||||||||||||||||
Updated: | 2011-09-07 | ||||||||||||||||||||||||
Summary: | The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2011-1407 Source: CCN Type: Packet Storm Web site Debian Security Advisory DSA-2236-1 Source: DEBIAN Type: UNKNOWN DSA-2236 Source: DEBIAN Type: DSA-2236 exim4 -- command injection Source: CCN Type: Exim Web site exim Internet Mailer Source: CCN Type: Gossamer Threads Web site Exim 4.76 Release: updated impact assessment Source: CCN Type: OSVDB ID: 72642 Exim DKIM Identity Lookup Item Remote Code Execution Source: BID Type: UNKNOWN 47836 Source: CCN Type: BID-47836 Exim DKIM CVE-2011-1407 Remote Code Execution Vulnerability Source: UBUNTU Type: UNKNOWN USN-1135-1 Source: XF Type: UNKNOWN exim-dkim-code-execution(67455) Source: MLIST Type: Patch [exim-announce] 20110509 Exim 4.76 Release Source: MLIST Type: Patch [exim-announce] 20110512 Exim 4.76 Release: updated impact assessment | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |