CVE-2024-39929

Source
https://cve.org/CVERecord?id=CVE-2024-39929
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39929.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39929
Downstream
Related
Published
2024-07-04T15:15:10.323Z
Modified
2026-04-02T12:17:16.660574Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

References

Affected packages

Git / github.com/exim/exim

Affected ranges

Type
GIT
Repo
https://github.com/exim/exim
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.97.1"
        }
    ]
}

Affected versions

Other
DEVEL_PDKIM_START
exim-4_50
exim-4_51
exim-4_52
exim-4_53
exim-4_54
exim-4_61
exim-4_62
exim-4_63
exim-4_64
exim-4_65
exim-4_66
exim-4_67
exim-4_68
exim-4_69
exim-4_70
exim-4_70_RC3
exim-4_70_RC4
exim-4_71
exim-4_72
exim-4_72_RC1
exim-4_72_RC2
exim-4_73
exim-4_73_RC0
exim-4_73_RC00
exim-4_73_RC1
exim-4_74
exim-4_74_RC1
exim-4_74_RC2
exim-4_75
exim-4_75_RC1
exim-4_75_RC2
exim-4_75_RC3
exim-4_76
exim-4_76_RC1
exim-4_76_RC2
exim-4_77
exim-4_77_RC1
exim-4_77_RC2
exim-4_77_RC3
exim-4_77_RC4
exim-4_80
exim-4_80_1
exim-4_80_RC1
exim-4_80_RC2
exim-4_80_RC3
exim-4_80_RC4
exim-4_80_RC5
exim-4_80_RC6
exim-4_80_RC7
exim-4_81_RC1
exim-4_82
exim-4_82_1
exim-4_82_RC1
exim-4_82_RC2
exim-4_82_RC3
exim-4_82_RC4
exim-4_82_RC5
exim-4_83
exim-4_83_RC1
exim-4_83_RC2
exim-4_83_RC3
exim-4_84
exim-4_84_1
exim-4_84_2
exim-4_84_RC1
exim-4_84_RC2
exim-4_85
exim-4_85_1
exim-4_85_2
exim-4_85_RC1
exim-4_85_RC2
exim-4_85_RC3
exim-4_85_RC4
exim-4_86
exim-4_86_1
exim-4_86_2
exim-4_86_RC1
exim-4_86_RC2
exim-4_86_RC3
exim-4_86_RC4
exim-4_86_RC5
exim-4_87
exim-4_87_1
exim-4_87_RC1
exim-4_87_RC2
exim-4_87_RC3
exim-4_87_RC4
exim-4_87_RC5
exim-4_87_RC6
exim-4_87_RC7
exim-4_88
exim-4_88_RC1
exim-4_88_RC2
exim-4_88_RC3
exim-4_88_RC4
exim-4_88_RC5
exim-4_88_RC6
exim-4_89
exim-4_89_1
exim-4_89_RC1
exim-4_89_RC2
exim-4_89_RC3
exim-4_89_RC4
exim-4_89_RC5
exim-4_89_RC6
exim-4_89_RC7
exim-4_90
exim-4_90_1
exim-4_90_RC1
exim-4_90_RC2
exim-4_90_RC3
exim-4_90_RC4
exim-4_91
exim-4_91_RC1
exim-4_91_RC2
exim-4_91_RC3
exim-4_91_RC4
exim-4_94_RC0
list_safety_merge_proposal
exim-4.*
exim-4.90.0.22
exim-4.90.0.27
exim-4.90devstart
exim-4.92
exim-4.92-RC1
exim-4.92-RC2
exim-4.92-RC3
exim-4.92-RC4
exim-4.92-RC5
exim-4.92-RC6
exim-4.92-jgh
exim-4.92.1
exim-4.92.1-RC2
exim-4.92.2
exim-4.92.2-RC1
exim-4.92.3
exim-4.92.3-RC1
exim-4.93
exim-4.93-RC0
exim-4.93-RC1
exim-4.93-RC2
exim-4.93-RC3
exim-4.93-RC4
exim-4.93-RC5
exim-4.93-RC6
exim-4.93-RC7
exim-4.93.0.1
exim-4.93.0.2
exim-4.93.0.3
exim-4.93.0.4
exim-4.94
exim-4.94-RC1
exim-4.94-RC2
exim-4.94.1
exim-4.94.2
exim-4.95
exim-4.95-RC0
exim-4.95-RC1
exim-4.95-RC2
exim-4.96
exim-4.96-RC0
exim-4.96-RC1
exim-4.96-RC2
exim-4.96.1
exim-4.96.2
exim-4.97
exim-4.97-RC0
exim-4.97-RC1
exim-4.97-RC2
exim-4.97-RC3
exim-4.97.1
exim-4.98
exim-4.98-RC0
exim-4.98-RC1
exim-4.98-RC2
exim-4.98-RC3
exim-4.98.1
exim-4.98.2
exim-4.99
exim-4.99-RC1
exim-4.99-RC2
exim-4.99-RC3
exim-4.99-RC4
exim-4.99.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39929.json"