CVE-2024-39929

Public on 2024-07-04
Modified on 2025-03-03
Description
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
Severity
Important severity
Important
CVSS v3 Base Score
7.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 exim No Fix Planned

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
NVD CVSSv3 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N