CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
Percentile
93.3%
The dmarc_process function in dmarc.c in Exim before 4.82.1, when
EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary
code via the From header in an email, which is passed to the expand_string
function.
Author | Note |
---|---|
jdstrand | EXPERIMENTAL_DMARC not enabled, ignoring |