CVE-2016-9963

Description

Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.678

Associated Vulnerability

VulnerabilityOS Platform
Exim is a mail transport agent (USN-1618-1) exim4-daemon-heavy_4.76-3ubuntu3.4_i386.debLinux
Exim is a mail transport agent (USN-1618-1) exim4-daemon-heavy_4.76-3ubuntu3.4_amd64.debLinux
Exim is a mail transport agent (USN-1618-1) exim4-daemon-light_4.76-3ubuntu3.4_i386.debLinux
Exim is a mail transport agent (USN-1618-1) exim4-daemon-light_4.76-3ubuntu3.4_amd64.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-heavy_4.76-3ubuntu3.4_i386.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-heavy_4.76-3ubuntu3.4_amd64.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-heavy_4.82-3ubuntu2.2_i386.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-heavy_4.82-3ubuntu2.2_amd64.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-heavy_4.87-3ubuntu1.1_i386.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-heavy_4.87-3ubuntu1.1_amd64.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-heavy_4.86.2-2ubuntu2.1_i386.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-heavy_4.86.2-2ubuntu2.1_amd64.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-light_4.76-3ubuntu3.4_i386.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-light_4.76-3ubuntu3.4_amd64.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-light_4.82-3ubuntu2.2_i386.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-light_4.82-3ubuntu2.2_amd64.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-light_4.87-3ubuntu1.1_i386.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-light_4.87-3ubuntu1.1_amd64.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-light_4.86.2-2ubuntu2.1_i386.debLinux
Exim is a mail transport agent (USN-3164-1) exim4-daemon-light_4.86.2-2ubuntu2.1_amd64.debLinux
exim4 security update(DSA-3747-1) exim4_4.84.2-2+deb8u2_all.debLinux
exim4 security update(DSA-3747-1) exim4_4.84.2-2+deb8u2_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234