CVE-2024-39929

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
Configurations

No configuration.

History

18 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-116

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://bugs.exim.org/show_bug.cgi?id=3099#c4 - () https://bugs.exim.org/show_bug.cgi?id=3099#c4 -
References () https://git.exim.org/exim.git/commit/1b3209b0577a9327ebb076f3b32b8a159c253f7b - () https://git.exim.org/exim.git/commit/1b3209b0577a9327ebb076f3b32b8a159c253f7b -
References () https://git.exim.org/exim.git/commit/6ce5c70cff8989418e05d01fd2a57703007a6357 - () https://git.exim.org/exim.git/commit/6ce5c70cff8989418e05d01fd2a57703007a6357 -
References () https://github.com/Exim/exim/compare/exim-4.98-RC2...exim-4.98-RC3 - () https://github.com/Exim/exim/compare/exim-4.98-RC2...exim-4.98-RC3 -
References () https://www.rfc-editor.org/rfc/rfc2231.txt - () https://www.rfc-editor.org/rfc/rfc2231.txt -

09 Jul 2024, 16:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

05 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Exim hasta la versión 4.97.1 analiza erróneamente un nombre de archivo de encabezado RFC 2231 multilínea y, por lo tanto, atacantes remotos pueden eludir un mecanismo de protección de bloqueo de extensión $mime_filename y potencialmente entregar archivos adjuntos ejecutables a los buzones de correo de los usuarios finales.

04 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-04 15:15

Updated : 2025-03-18 16:15


NVD link : CVE-2024-39929

Mitre link : CVE-2024-39929

CVE.ORG link : CVE-2024-39929


JSON object : View

Products Affected

No product.

CWE
CWE-116

Improper Encoding or Escaping of Output