CVE-2024-39929
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.
- Affected products
- Astra Linux, Exim, Linuxmint, Red Os, Ubuntu
- Exim
- β€ 4.97.1
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 41.2% (99th percentile)
- Weakness
- CWE-116
- NVD status
- Analyzed
- Published
- 2024-07-04
CVE-2024-39929 at NVD
7 known exploits for CVE-2024-39929
Proof-of-concept code and exploit modules indexed by Sploitus