CVE-2005-0021
exim-tls - buffer overflow
EPSS 2.6%
描述
Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.
如何修補 CVE-2005-0021
要修補 CVE-2005-0021,請將受影響套件升級到下列已修補版本。
- Debian/exim—升級至 3.35-1woody4 或更新版本
- Debian/exim-tls—升級至 3.35-3woody3 或更新版本
- —升級至 4.34-10 或更新版本
CVE-2005-0021 正在被利用嗎?
低 — EPSS 為 2.6%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 3.35-1woody4
- from 0, < 3.35-3woody3
- from 0, < 4.34-10