Critical Exim GnuTLS Flaw Enables Remote Code Execution
ID: b91de77f-2160-55d6-92c1-9963054e8222
STIX ID: report--b91de77f-2160-55d6-92c1-9963054e8222
Feed Name: Cyber Press
Threat Score
**Executive summary:** A critical use‑after‑free vulnerability was disclosed in Exim's GnuTLS backend (affecting Exim 4.97 through 4.99.2 when compiled with GnuTLS) that can be triggered by sending a TLS close_notify during a BDAT chunked SMTP transfer, allowing remote attackers to corrupt heap memory and potentially achieve arbitrary code execution; Exim 4.99.3 was released to fix the issue and administrators should urgently upgrade as no configuration workaround exists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
