CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
97.9%
Debian Security Advisory DSA-2566-1 [email protected]
http://www.debian.org/security/ Nico Golde
October 25, 2012 http://www.debian.org/security/faq
Package : exim4
Vulnerability : heap-based buffer overflow
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-5671
It was discovered that Exim, a mail transport agent, is not properly
handling the decoding of DNS records for DKIM. Specifically, crafted
records can yield to a heap-based buffer overflow. An attacker can
exploit this flaw to execute arbitrary code.
For the stable distribution (squeeze), this problem has been fixed in
version 4.72-6+squeeze3.
For the testing distribution (wheezy), this problem has been fixed in
version 4.80-5.1.
For the unstable distribution (sid), this problem has been fixed in
version 4.80-5.1.
We recommend that you upgrade your exim4 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: [email protected]
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 6 | kfreebsd-amd64 | exim4-daemon-heavy-dbg | < 4.72-6+squeeze3 | exim4-daemon-heavy-dbg_4.72-6+squeeze3_kfreebsd-amd64.deb |
Debian | 6 | kfreebsd-i386 | exim4-dbg | < 4.72-6+squeeze3 | exim4-dbg_4.72-6+squeeze3_kfreebsd-i386.deb |
Debian | 6 | i386 | exim4-dbg | < 4.72-6+squeeze3 | exim4-dbg_4.72-6+squeeze3_i386.deb |
Debian | 6 | mips | exim4-dev | < 4.72-6+squeeze3 | exim4-dev_4.72-6+squeeze3_mips.deb |
Debian | 6 | sparc | exim4-daemon-heavy-dbg | < 4.72-6+squeeze3 | exim4-daemon-heavy-dbg_4.72-6+squeeze3_sparc.deb |
Debian | 6 | powerpc | exim4-dev | < 4.72-6+squeeze3 | exim4-dev_4.72-6+squeeze3_powerpc.deb |
Debian | 6 | powerpc | exim4-base | < 4.72-6+squeeze3 | exim4-base_4.72-6+squeeze3_powerpc.deb |
Debian | 6 | powerpc | exim4-daemon-heavy | < 4.72-6+squeeze3 | exim4-daemon-heavy_4.72-6+squeeze3_powerpc.deb |
Debian | 6 | amd64 | exim4-dev | < 4.72-6+squeeze3 | exim4-dev_4.72-6+squeeze3_amd64.deb |
Debian | 6 | s390 | exim4-daemon-light | < 4.72-6+squeeze3 | exim4-daemon-light_4.72-6+squeeze3_s390.deb |