CVE Vulnerabilities

CVE-2016-9963

Published: Feb 01, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.

Affected Software

NameVendorStart VersionEnd Version
EximExim*4.87 (including)
Exim4Ubuntudevel*
Exim4Ubuntuesm-infra-legacy/trusty*
Exim4Ubuntuesm-infra/xenial*
Exim4Ubuntuprecise*
Exim4Ubuntutrusty*
Exim4Ubuntutrusty/esm*
Exim4Ubuntuupstream*
Exim4Ubuntuxenial*
Exim4Ubuntuyakkety*

References