CVE Vulnerabilities

CVE-2011-1764

Use of Externally-Controlled Format String

Published: Oct 05, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

NameVendorStart VersionEnd Version
EximExim*4.75 (including)
EximExim2.10 (including)2.10 (including)
EximExim2.11 (including)2.11 (including)
EximExim2.12 (including)2.12 (including)
EximExim3.00 (including)3.00 (including)
EximExim3.01 (including)3.01 (including)
EximExim3.02 (including)3.02 (including)
EximExim3.03 (including)3.03 (including)
EximExim3.10 (including)3.10 (including)
EximExim3.11 (including)3.11 (including)
EximExim3.12 (including)3.12 (including)
EximExim3.13 (including)3.13 (including)
EximExim3.14 (including)3.14 (including)
EximExim3.15 (including)3.15 (including)
EximExim3.16 (including)3.16 (including)
EximExim3.20 (including)3.20 (including)
EximExim3.21 (including)3.21 (including)
EximExim3.22 (including)3.22 (including)
EximExim3.30 (including)3.30 (including)
EximExim3.31 (including)3.31 (including)
EximExim3.32 (including)3.32 (including)
EximExim3.33 (including)3.33 (including)
EximExim3.34 (including)3.34 (including)
EximExim3.35 (including)3.35 (including)
EximExim3.36 (including)3.36 (including)
EximExim4.00 (including)4.00 (including)
EximExim4.01 (including)4.01 (including)
EximExim4.02 (including)4.02 (including)
EximExim4.03 (including)4.03 (including)
EximExim4.04 (including)4.04 (including)
EximExim4.05 (including)4.05 (including)
EximExim4.10 (including)4.10 (including)
EximExim4.11 (including)4.11 (including)
EximExim4.12 (including)4.12 (including)
EximExim4.14 (including)4.14 (including)
EximExim4.20 (including)4.20 (including)
EximExim4.21 (including)4.21 (including)
EximExim4.22 (including)4.22 (including)
EximExim4.23 (including)4.23 (including)
EximExim4.24 (including)4.24 (including)
EximExim4.30 (including)4.30 (including)
EximExim4.31 (including)4.31 (including)
EximExim4.32 (including)4.32 (including)
EximExim4.33 (including)4.33 (including)
EximExim4.34 (including)4.34 (including)
EximExim4.40 (including)4.40 (including)
EximExim4.41 (including)4.41 (including)
EximExim4.42 (including)4.42 (including)
EximExim4.43 (including)4.43 (including)
EximExim4.44 (including)4.44 (including)
EximExim4.50 (including)4.50 (including)
EximExim4.51 (including)4.51 (including)
EximExim4.52 (including)4.52 (including)
EximExim4.53 (including)4.53 (including)
EximExim4.54 (including)4.54 (including)
EximExim4.60 (including)4.60 (including)
EximExim4.61 (including)4.61 (including)
EximExim4.62 (including)4.62 (including)
EximExim4.63 (including)4.63 (including)
EximExim4.64 (including)4.64 (including)
EximExim4.65 (including)4.65 (including)
EximExim4.66 (including)4.66 (including)
EximExim4.67 (including)4.67 (including)
EximExim4.68 (including)4.68 (including)
EximExim4.69 (including)4.69 (including)
EximExim4.70 (including)4.70 (including)
EximExim4.71 (including)4.71 (including)
EximExim4.72 (including)4.72 (including)
EximExim4.73 (including)4.73 (including)
EximExim4.74 (including)4.74 (including)
Exim4Ubuntulucid*
Exim4Ubuntumaverick*
Exim4Ubuntunatty*
Exim4Ubuntuupstream*

Potential Mitigations

References