SMTP: Exim SMTP Listener User Overflow

This signature detects attempts to exploit a known vulnerability against Exim SMTP listener. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.

Affected Products

Exim exim

References

CVE: CVE-2018-6789

Short Name
SMTP:EMAIL:EXIM-LISTEN-OVERFLOW
Severity
Info
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
CVE-2018-6789 Exim Listener Overflow SMTP User
Release Date
05/06/2025
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3806
False Positive
Occasionally
Vendors

Exim

Found a potential security threat?