This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.
The remote mail server is potentially affected by a buffer overflow
According to its banner, the version of Exim running on the remote host
is between 4.70 and 4.80 inclusive. It therefore is potentially
affected by a remote, heap-based buffer overflow vulnerability when
decoding DKIM (DomainKeys Identified Mail) DNS records that can be
triggered by a specially crafted email sent from a domain under the
By exploiting this flaw, a remote, unauthenticated attacker could
execute arbitrary code on the remote host subject to the privileges of
the user running the affected application.
Note that this issue is only exploitable when exim is built with DKIM
support, which is true by default, and has not been disabled. Note too
that Nessus has not checked whether either condition is true.
See also :
Upgrade to Exim 4.80.1 or later.
Risk factor :
High / CVSS Base Score : 7.5
CVSS Temporal Score : 6.5
Public Exploit Available : false
Family: SMTP problems
Nessus Plugin ID: 62734 ()
Bugtraq ID: 56285
CVE ID: CVE-2012-5671
Upgrade to Nessus Professional today!
Start your free Nessus Cloud trial now!
Begin Free Trial
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.