Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-2957
HistorySep 04, 2014 - 12:00 a.m.

CVE-2014-2957

2014-09-0400:00:00
ubuntu.com
ubuntu.com
9

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.056

Percentile

93.3%

The dmarc_process function in dmarc.c in Exim before 4.82.1, when
EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary
code via the From header in an email, which is passed to the expand_string
function.

Notes

Author Note
jdstrand EXPERIMENTAL_DMARC not enabled, ignoring

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.056

Percentile

93.3%