home tags events about login
one honk maybe more

tedu honked 06 Jun 2019 07:34 -0400

This is a joyous quote.

This vulnerability is exploitable instantly by a local attacker (and by a remote attacker in certain non-default configurations). To remotely exploit this vulnerability in the default configuration, an attacker must keep a connection to the vulnerable server open for 7 days (by transmitting one byte every few minutes). However, because of the extreme complexity of Exim's code, we cannot guarantee that this exploitation method is unique; faster methods may exist.


https://marc.info/?l=oss-security&m=155975574208903&w=2