CVE-2021-38371

Updated: 2022-05-25 08:39:59.161765

Description:

The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 6 ELS exim 4.94.2 7.5 HIGH Needs Triage 2021-12-09 07:57:03
CentOS 8.4 ELS exim 4.94.2-2 7.5 HIGH Needs Triage 2022-02-10 11:47:48
CentOS 8.5 ELS exim 4.94.2-2 7.5 HIGH Needs Triage 2022-02-10 11:47:49
CloudLinux 6 ELS exim 4.94.2 7.5 HIGH Needs Triage 2021-12-09 07:57:03
Oracle Linux 6 ELS exim 4.94.2 7.5 HIGH Needs Triage 2021-12-17 07:40:05
Ubuntu 16.04 ELS exim 4.86.2-2 7.5 HIGH Needs Triage 2021-12-20 10:40:08
Ubuntu 18.04 ELS exim 4.90.1-1 7.5 HIGH Needs Triage 2023-03-02 13:01:01