Description: A vulnerability has been identified in Exim, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system or compromise it.
The vulnerability is caused due to a boundary error when handling input to the HELO and EHLO commands. This can be exploited to cause a heap overflow by supplying an argument containing 500 or more spaces followed by a NULL byte and CRLF (carriage return, line feed).
Successful exploitation might allow execution of arbitrary code on a vulnerable system. However, this has not been confirmed and the vulnerability is not currently thought to be exploitable.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.