CVE-2003-0743

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/10/2003
Last modified:
18/10/2016

Description

Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:university_of_cambridge:exim:3.0:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.3:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.11:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.12:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.13:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.14:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.15:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.16:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.17:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.18:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.19:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.20:*:*:*:*:*:*:*
cpe:2.3:a:university_of_cambridge:exim:3.21:*:*:*:*:*:*:*