Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Aug 2024 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2010-12-14T15:00:00
Updated: 2024-08-07T03:43:14.654Z
Reserved: 2010-11-30T00:00:00
Link: CVE-2010-4344
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2010-12-14T16:00:04.163
Modified: 2024-12-19T18:21:15.367
Link: CVE-2010-4344
Redhat