CVE Vulnerabilities

CVE-2024-39929

Published: Jul 04, 2024 | Modified: Jul 09, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

Affected Software

Name Vendor Start Version End Version
Exim4 Ubuntu devel *
Exim4 Ubuntu esm-infra/bionic *
Exim4 Ubuntu esm-infra/xenial *
Exim4 Ubuntu focal *
Exim4 Ubuntu jammy *
Exim4 Ubuntu mantic *
Exim4 Ubuntu noble *

References