{"id":"CVE-2017-16943","details":"The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.","modified":"2026-07-08T05:49:52.011251667Z","published":"2017-11-25T17:29:00.260Z","related":["openSUSE-SU-2021:0677-1","openSUSE-SU-2021:0753-1","openSUSE-SU-2021:0754-1","openSUSE-SU-2024:10746-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2021/05/04/7"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1039872"},{"type":"ADVISORY","url":"https://www.debian.org/security/2017/dsa-4053"},{"type":"REPORT","url":"https://bugs.exim.org/show_bug.cgi?id=2199"},{"type":"FIX","url":"https://git.exim.org/exim.git/commit/4090d62a4b25782129cc1643596dc2f6e8f63bde"},{"type":"FIX","url":"https://git.exim.org/exim.git/commitdiff/4e6ae6235c68de243b1c2419027472d7659aa2b4"},{"type":"ARTICLE","url":"http://openwall.com/lists/oss-security/2017/11/25/1"},{"type":"ARTICLE","url":"http://openwall.com/lists/oss-security/2017/11/25/2"},{"type":"ARTICLE","url":"http://openwall.com/lists/oss-security/2017/11/25/3"},{"type":"ARTICLE","url":"https://lists.exim.org/lurker/message/20171125.034842.d1d75cac.en.html"},{"type":"EVIDENCE","url":"https://github.com/LetUsFsck/PoC-Exploit-Mirror/tree/master/CVE-2017-16944"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/exim/exim","events":[{"introduced":"57091745e6d5ce4259c645b3ac63838668d55b7f"},{"last_affected":"38903fb5b864ee99904d035337c66891604d9678"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:exim:exim:4.88:-:*:*:*:*:*:*","cpe:2.3:a:exim:exim:4.89:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.88-NA"},{"last_affected":"4.88-NA"},{"introduced":"4.89-NA"},{"last_affected":"4.89-NA"}]}}],"versions":["4.88-NA","4.89-NA","exim-4_89","exim-4_89_RC7","exim-4_89_RC6","exim-4_89_RC5","exim-4_89_RC4","exim-4_89_RC3","exim-4_89_RC1","exim-4_88"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16943.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}