CVE-2014-2957

EPSS 1.8%
Published: 9/4/2014Modified: 4/28/2026
Also known as:DEBIAN-CVE-2014-2957

Description

The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.

Affected packages (1)

References (1)