SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Exim4 string_format Function Heap Buffer Overflow

Category: SMTP      

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4344


Relevant Information