Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.70843
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-1130-1 (exim4-daemon-custom)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to exim4-daemon-custom
announced via advisory USN-1130-1.

Details:

It was discovered that the Exim daemon did not correctly handle format
strings in DKIM headers. An unauthenticated remote attacker could send
specially crafted email to run arbitrary code as the Exim user. The
default compiler options for affected releases reduces the vulnerability
to a denial of service under most conditions.

Solution:
The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
exim4-daemon-custom 4.74-1ubuntu1.1
exim4-daemon-heavy 4.74-1ubuntu1.1
exim4-daemon-light 4.74-1ubuntu1.1

Ubuntu 10.10:
exim4-daemon-custom 4.72-1ubuntu1.2
exim4-daemon-heavy 4.72-1ubuntu1.2
exim4-daemon-light 4.72-1ubuntu1.2

Ubuntu 10.04 LTS:
exim4-daemon-custom 4.71-3ubuntu1.2
exim4-daemon-heavy 4.71-3ubuntu1.2
exim4-daemon-light 4.71-3ubuntu1.2

http://www.securityspace.com/smysecure/catid.html?in=USN-1130-1

CVSS Score:
7.5

CVSS Vector:
AV:L/AC:L/Au:NR/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1764
Debian Security Information: DSA-2232 (Google Search)
http://www.debian.org/security/2011/dsa-2232
http://secunia.com/advisories/51155
SuSE Security Announcement: SUSE-SR:2011:009 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.