Executive Summary
Summary | |
---|---|
Title | New exim packages fix incorrect permissions on documentation |
Informations | |||
---|---|---|---|
Name | DSA-376 | First vendor Publication | 2003-09-07 |
Vendor | Debian | Last vendor Modification | 2003-09-07 |
Severity (Vendor) | N/A | Revision | 2 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A buffer overflow exists in exim, which is the standard mail transport agent in Debian. By supplying a specially crafted HELO or EHLO command, an attacker could cause a constant string to be written past the end of a buffer allocated on the heap. This vulnerability is not believed at this time to be exploitable to execute arbitrary code. The exim package included in the previous advisory contained some documentation files which were installed with incorrect permissions. This problem is fixed in exim 3.35-1woody2. For the stable distribution (woody) this problem has been fixed in exim version 3.35-1woody2 and exim-tls version 3.35-3woody1. For the unstable distribution (sid) this problem has been fixed in exim version 3.36-8. The unstable distribution does not contain an exim-tls package. We recommend that you update your exim or exim-tls package. |
Original Source
Url : http://www.debian.org/security/2003/dsa-376 |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 376-1 (exim exim-tls) File : nvt/deb_376_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
10877 | Exim smtp_in.c HELO/EHLO Remote Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-376.nasl - Type : ACT_GATHER_INFO |
2003-09-02 | Name : The remote SMTP server has a heap-based buffer overflow vulnerability. File : exim_heap_overflow.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:32:52 |
|