Buffer overflow in the spabase64tobits function in Exim before 4.43, as originally obtained from Samba code, and as called by the authspa_client function, may allow attackers to execute arbitrary code during SPA authentication.
{ "urgency": "not yet assigned" }