CLEANSTART-2025-LU26051

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2025/CLEANSTART-2025-LU26051.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2025-LU26051
Upstream
Published
2026-10-01T08:01:54Z
Modified
2026-10-01T09:15:57Z
Severity
  • 4.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution
Details

Security vulnerability affects the exim package. Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution.

References

Affected packages

CleanStart / exim

Package

Name
exim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.89-r5

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2025/CLEANSTART-2025-LU26051.json"