Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2014-2957

Published: 4 September 2014

The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.

Notes

AuthorNote
jdstrand
EXPERIMENTAL_DMARC not enabled, ignoring

Priority

Negligible

Status

Package Release Status
exim4
Launchpad, Ubuntu, Debian
lucid Not vulnerable
(code not present)
precise Not vulnerable
(code not present)
saucy Ignored
(end of life)
trusty Ignored

upstream
Released (4.82.1-1)