Exim Pipe Hostname Arbitrary Command Execution Vulnerability

BID:3728

Info

Exim Pipe Hostname Arbitrary Command Execution Vulnerability

Bugtraq ID: 3728
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Dec 19 2001 12:00AM
Updated: Dec 19 2001 12:00AM
Credit: This vulnerability was originally discovered by Patrice Fournier, and announced by Philip Hazel <[email protected]> via the exim-users and exim-announce mailing lists on December 19, 2001.
Vulnerable: University of Cambridge Exim 3.33
University of Cambridge Exim 3.32
University of Cambridge Exim 3.31
University of Cambridge Exim 3.30
University of Cambridge Exim 3.22
- Redhat PowerTools 7.1
University of Cambridge Exim 3.21
University of Cambridge Exim 3.20
University of Cambridge Exim 3.19
- Redhat PowerTools 7.0
University of Cambridge Exim 3.18
University of Cambridge Exim 3.17
University of Cambridge Exim 3.16
University of Cambridge Exim 3.15
University of Cambridge Exim 3.14
University of Cambridge Exim 3.13
- Redhat PowerTools 6.2
University of Cambridge Exim 3.12
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 IA-32
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
University of Cambridge Exim 3.11
Not Vulnerable: University of Cambridge Exim 3.952
University of Cambridge Exim 3.34

Discussion

Exim Pipe Hostname Arbitrary Command Execution Vulnerability

Exim is a Mail Transport Agent designed with security in mind. It is freely avaiable, open source, and distributed by the University of Cambridge.

When Exim receives a mail, it processes the mail by it's localhost and domain name. In the event that the mail contains a pipe (|) symbol as the first part of it's host name, Exim attempts to interpret the localhost name as a command. This could result in a mail with a maliciously crafted From: field being used to execute a command contained within the localhost name of the mailing host. This problem only affects configurations that routes or directs mail without performing any type of check on the local part of the address, and does not affect alias or forward files.

Exploit / POC

Exim Pipe Hostname Arbitrary Command Execution Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Exim Pipe Hostname Arbitrary Command Execution Vulnerability

Solution:
Fixed versions available:


University of Cambridge Exim 3.11

University of Cambridge Exim 3.12

University of Cambridge Exim 3.13

University of Cambridge Exim 3.14

University of Cambridge Exim 3.15

University of Cambridge Exim 3.16

University of Cambridge Exim 3.17

University of Cambridge Exim 3.18

University of Cambridge Exim 3.19

University of Cambridge Exim 3.20

University of Cambridge Exim 3.21

University of Cambridge Exim 3.22

University of Cambridge Exim 3.30

University of Cambridge Exim 3.31

University of Cambridge Exim 3.32

University of Cambridge Exim 3.33

References

Exim Pipe Hostname Arbitrary Command Execution Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report