CVE-2010-4344

CVE Published 2010-12-14
Related CWE(s) CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer, CWE-787: Out-of-bounds Write
Related Vendor(s) debian, exim, opensuse, canonical
Related Product(s) debian_linux, exim, opensuse, ubuntu_linux
Exploitation Reported (CISA KEV) 2022-03-25
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References