CyberSec.Space Logo
CVEブラウザに戻る

CVE-2010-4344

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score82.0680%
EPSS Percentile86.90th
Published2010年12月14日
Last Modified2026年4月21日

Vulnerability Description

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

Affected Platforms (CPE)

📦
Exim

Exim

< 4.70
💻
Opensuse

Opensuse

= 11.1
💻
Opensuse

Opensuse

= 11.2
💻
Opensuse

Opensuse

= 11.3
💻
Debian

Debian Linux

= 5.0
💻
Canonical

Ubuntu Linux

= 6.06
💻
Canonical

Ubuntu Linux

= 8.04
💻
Canonical

Ubuntu Linux

= 9.10

References & Advisories

関連する脆弱性情報