2025-03-18 17:03:48 +00:00

96 lines
3.2 KiB
JSON

{
"id": "CVE-2024-39929",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-07-04T15:15:10.323",
"lastModified": "2025-03-18T16:15:21.850",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users."
},
{
"lang": "es",
"value": "Exim hasta la versi\u00f3n 4.97.1 analiza err\u00f3neamente un nombre de archivo de encabezado RFC 2231 multil\u00ednea y, por lo tanto, atacantes remotos pueden eludir un mecanismo de protecci\u00f3n de bloqueo de extensi\u00f3n $mime_filename y potencialmente entregar archivos adjuntos ejecutables a los buzones de correo de los usuarios finales."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 2.5
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-116"
}
]
}
],
"references": [
{
"url": "https://bugs.exim.org/show_bug.cgi?id=3099#c4",
"source": "cve@mitre.org"
},
{
"url": "https://git.exim.org/exim.git/commit/1b3209b0577a9327ebb076f3b32b8a159c253f7b",
"source": "cve@mitre.org"
},
{
"url": "https://git.exim.org/exim.git/commit/6ce5c70cff8989418e05d01fd2a57703007a6357",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/Exim/exim/compare/exim-4.98-RC2...exim-4.98-RC3",
"source": "cve@mitre.org"
},
{
"url": "https://www.rfc-editor.org/rfc/rfc2231.txt",
"source": "cve@mitre.org"
},
{
"url": "https://bugs.exim.org/show_bug.cgi?id=3099#c4",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.exim.org/exim.git/commit/1b3209b0577a9327ebb076f3b32b8a159c253f7b",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.exim.org/exim.git/commit/6ce5c70cff8989418e05d01fd2a57703007a6357",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/Exim/exim/compare/exim-4.98-RC2...exim-4.98-RC3",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.rfc-editor.org/rfc/rfc2231.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}