CVE-2018-6789
Description
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
In plain language
AI Act nowThis is a serious Exim email server flaw where a specially made email can cause the server to crash or run attacker code remotely; most small businesses that run Exim should treat this as urgent and upgrade.
Exim before 4.90.1 has a buffer overflow in the base64d function in its SMTP listener; it can be triggered remotely with a crafted message without authentication, enabling remote code execution.
What to do now
- Check whether you run Exim and its version is older than 4.90.1.
- If Exim is in use and vulnerable, upgrade Exim to 4.90.1 or later using your distro’s recommended update path.
- Confirm the SMTP service is restarted after the update and verify the running Exim version.
- If you cannot upgrade immediately, temporarily restrict inbound SMTP connections (port 25 and related submission/relay ports) to only trusted networks/hosts until the update is applied.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-6789 and every CVE in our database. Create a free account — no credit card required.
Create Free Account