CVE Vulnerabilities

CVE-2003-0743

Published: Oct 20, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the (no argument given) string is appended to the buffer.

Affected Software

NameVendorStart VersionEnd Version
EximUniversity_of_cambridge3.0 (including)3.0 (including)
EximUniversity_of_cambridge3.3 (including)3.3 (including)
EximUniversity_of_cambridge3.3.1 (including)3.3.1 (including)
EximUniversity_of_cambridge3.3.2 (including)3.3.2 (including)
EximUniversity_of_cambridge3.11 (including)3.11 (including)
EximUniversity_of_cambridge3.12 (including)3.12 (including)
EximUniversity_of_cambridge3.13 (including)3.13 (including)
EximUniversity_of_cambridge3.14 (including)3.14 (including)
EximUniversity_of_cambridge3.15 (including)3.15 (including)
EximUniversity_of_cambridge3.16 (including)3.16 (including)
EximUniversity_of_cambridge3.17 (including)3.17 (including)
EximUniversity_of_cambridge3.18 (including)3.18 (including)
EximUniversity_of_cambridge3.19 (including)3.19 (including)
EximUniversity_of_cambridge3.20 (including)3.20 (including)
EximUniversity_of_cambridge3.21 (including)3.21 (including)
EximUniversity_of_cambridge3.22 (including)3.22 (including)
EximUniversity_of_cambridge3.30 (including)3.30 (including)
EximUniversity_of_cambridge3.31 (including)3.31 (including)
EximUniversity_of_cambridge3.32 (including)3.32 (including)
EximUniversity_of_cambridge3.33 (including)3.33 (including)
EximUniversity_of_cambridge3.34 (including)3.34 (including)
EximUniversity_of_cambridge3.35 (including)3.35 (including)
EximUniversity_of_cambridge3.36 (including)3.36 (including)
EximUniversity_of_cambridge4.10 (including)4.10 (including)
EximUniversity_of_cambridge4.20 (including)4.20 (including)

References