CVE-2010-4344
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Exim email server has a critical flaw where a specially crafted email with certain headers can cause a buffer overflow, allowing attackers to run arbitrary code on the server through SMTP.
Heap-based buffer overflow in the string_vformat function in Exim <4.70 exploitable via SMTP by sending two consecutive MAIL commands followed by a large message with crafted headers; improper rejection logging triggers the memory corruption, enabling remote code execution without authentication.
The full analysis of this CVE is available in Portuguese →