CVE-2003-0743
published 2003-10-20CVE-2003-0743: Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.51%
91.8th percentile
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
| university_of_cambridge | exim | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000735http://marc.info/?l=bugtraq&m=106252015820395&w=2http://marc.info/?l=vuln-dev&m=106264740820334&w=2http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changeloghttp://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changeloghttp://www.debian.org/security/2003/dsa-376http://www.exim.org/pipermail/exim-announce/2003q3/000094.htmlhttp://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057720.htmlhttp://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057809.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000735http://marc.info/?l=bugtraq&m=106252015820395&w=2http://marc.info/?l=vuln-dev&m=106264740820334&w=2http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changeloghttp://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changeloghttp://www.debian.org/security/2003/dsa-376http://www.exim.org/pipermail/exim-announce/2003q3/000094.htmlhttp://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057720.htmlhttp://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057809.html
2003-10-20
Published