CVE-2018-6789

CVE Published 2018-02-08
Related CWE(s) CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Related Vendor(s) debian, exim, canonical
Related Product(s) exim, ubuntu_linux, debian_linux
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References