← Retour à la recherche de CVE

CVE-2026-40684

Exim

Description

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

CVSS 5.9EPSS 0.362%Risque 0.61
Voir la source
Publication
2026-04-30 22:16:25
Versions concernées
<4.99.2
Type
Core software
Vecteur
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H