CVE-2024-39929

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/07/2024
Last modified:
10/07/2025

Description

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* 4.97.1 (including)