Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2003-0743
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2003-0743

Description:
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.

CVE Status:
Candidate

References:

VULN-DEV
  http://marc.theaimsgroup.com/?l=vuln-dev&m=106264740820334&w=2

MLIST
  http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057720.html
  http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057809.html

DEBIAN
  http://www.debian.org/security/2003/dsa-376

CONFIRM
  http://www.exim.org/pipermail/exim-announce/2003q3/000094.html
  http://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changelog
  http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changelog

CONECTIVA
  http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000735

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=106252015820395&w=2


Return to the previous page.