CVE-2018-6789
exim, debian linux, canonical ubuntu linux
Published 8 Feb 2018 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
References
- openwall.com/lists/oss-security/2018/02/10/2 · Mailing List, Third Party Advisory
- packetstormsecurity.com/files/162959/Exim-base64d-Buffer-Overflow.html · Exploit, Third Party Advisory, VDB Entry
- www.openwall.com/lists/oss-security/2018/02/07/2 · Mailing List, Third Party Advisory
- www.securityfocus.com/bid/103049 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1040461 · Broken Link, Third Party Advisory, VDB Entry
- devco.re/blog/2018/03/06/exim-off-by-one-RCE-exploiting-CVE-2018-6789-en/ · Exploit, Third Party Advisory
- exim.org/static/doc/security/CVE-2018-6789.txt · Vendor Advisory
- git.exim.org/exim.git/commit/cf3cd306062a08969c41a1cdd32c6855f1abecf1 · Patch
- lists.debian.org/debian-lts-announce/2018/02/msg00009.html · Mailing List, Third Party Advisory
- usn.ubuntu.com/3565-1/ · Third Party Advisory
- www.debian.org/security/2018/dsa-4110 · Mailing List, Third Party Advisory
- www.exploit-db.com/exploits/44571/ · Exploit, Third Party Advisory, VDB Entry
- www.exploit-db.com/exploits/45671/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-6789 · US Government Resource