CVE-2011-1407

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-1407
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2011-1407.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2011-1407
Related
Published
2011-05-16T18:55:00Z
Modified
2024-09-18T01:00:22Z
Summary
[none]
Details

The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.

References

Affected packages

Debian:11 / exim4

Package

Name
exim4
Purl
pkg:deb/debian/exim4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.76-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / exim4

Package

Name
exim4
Purl
pkg:deb/debian/exim4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.76-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / exim4

Package

Name
exim4
Purl
pkg:deb/debian/exim4?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.76-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}