CVE-2011-1764

Publication date 10 May 2011

Last updated 24 July 2024


Ubuntu priority

Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.

Status

Package Ubuntu Release Status
exim4 11.04 natty
Fixed 4.74-1ubuntu1.1
10.10 maverick
Fixed 4.72-1ubuntu1.2
10.04 LTS lucid
Fixed 4.71-3ubuntu1.2
8.04 LTS hardy
Not affected
6.06 LTS dapper
Not affected

References

Related Ubuntu Security Notices (USN)

Other references