CVE Vulnerabilities

CVE-2016-9963

Published: Feb 01, 2017 | Modified: Feb 15, 2017
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM

Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.

Affected Software

Name Vendor Start Version End Version
Exim Exim * 4.87 (including)
Exim4 Ubuntu devel *
Exim4 Ubuntu precise *
Exim4 Ubuntu trusty *
Exim4 Ubuntu upstream *
Exim4 Ubuntu xenial *
Exim4 Ubuntu yakkety *

References