CVE-2014-2957
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-2957
Vendor advisory: cret@cert.org — https://lists.exim.org/lurker/message/20140528.122536.a31d60a4.en.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 4.82.1-1 |
| debian | bullseye | fixed | 4.82.1-1 |
| debian | forky | fixed | 4.82.1-1 |
| debian | sid | fixed | 4.82.1-1 |
| debian | trixie | fixed | 4.82.1-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| exim | exim | 4.23 | |
| exim | exim | {"endIncluding":"4.82"} | |
| exim | exim | 4.00 | |
| exim | exim | 4.01 | |
| exim | exim | 4.02 | |
| exim | exim | 4.03 | |
| exim | exim | 4.04 | |
| exim | exim | 4.05 | |
| exim | exim | 4.10 | |
| exim | exim | 4.11 | |
| exim | exim | 4.12 | |
| exim | exim | 4.14 | |
| exim | exim | 4.20 | |
| exim | exim | 4.21 | |
| exim | exim | 4.22 | |
| exim | exim | 4.24 | |
| exim | exim | 4.30 | |
| exim | exim | 4.31 | |
| exim | exim | 4.32 | |
| exim | exim | 4.33 | |
| exim | exim | 4.34 | |
| exim | exim | 4.40 | |
| exim | exim | 4.41 | |
| exim | exim | 4.42 | |
| exim | exim | 4.43 | |
| exim | exim | 4.44 | |
| exim | exim | 4.50 | |
| exim | exim | 4.51 | |
| exim | exim | 4.52 | |
| exim | exim | 4.53 | |
| exim | exim | 4.54 | |
| exim | exim | 4.60 | |
| exim | exim | 4.61 | |
| exim | exim | 4.62 | |
| exim | exim | 4.63 | |
| exim | exim | 4.64 | |
| exim | exim | 4.65 | |
| exim | exim | 4.66 | |
| exim | exim | 4.67 | |
| exim | exim | 4.68 | |
| exim | exim | 4.69 | |
| exim | exim | 4.70 | |
| exim | exim | 4.71 | |
| exim | exim | 4.72 | |
| exim | exim | 4.73 | |
| exim | exim | 4.74 | |
| exim | exim | 4.75 | |
| exim | exim | 4.76 | |
| exim | exim | 4.77 | |
| exim | exim | 4.80 | |
| exim | exim | 4.80.1 | |
References
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.