CVE-2012-5671

medium
Published 2012-10-31 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-5671

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/51098

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.80-5.1
debian debianbullseyefixed4.80-5.1
debian debianforkyfixed4.80-5.1
debian debiansidfixed4.80-5.1
debian debiantrixiefixed4.80-5.1

Application impact

VendorProductVersionsFixed
eximexim4.70
eximexim4.71
eximexim4.72
eximexim4.73
eximexim4.74
eximexim4.75
eximexim4.76
eximexim4.77
eximexim4.80

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.