CVE-2018-6789 is a critical buffer overflow vulnerability (CWE-120) in the base64d function of the Exim SMTP listener, affecting Exim versions prior to 4.90.1 and various Debian/Ubuntu distributions. This flaw allows for unauthenticated remote code execution via a crafted message, posing a severe risk with a CVSS score of 9.8. The vulnerability is actively exploited, including in known ransomware campaigns, and has public exploit code available on ExploitDB. It has garnered significant community discussion and media attention, including being listed by the NSA as actively abused by Chinese state-sponsored hackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.90.1CPE matchmatch criteria | cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
exim: buffer overflow in b64decode() function, possibly leading to remote code execution
Feb 7, 2018Security Advisory for CVE-2018-6789
Security Advisory for CVE-2018-6789