I received this message from a Nessus scan. Has anyone else seen or heard anything about it?
Exim < 4.22 smtp_in.c HELO/EHLO Remote Overflow
Synopsis :
The remote SMTP server has a heap buffer overflow vulnerability.
Description :
According to its banner, the version of Exim running on the remote
host has a remote heap buffer overflow vulnerability. A remote,
unauthenticated attacker could potentially exploit this to execute
arbitrary code.
See also :
https://lists.exim.org/lurker/message/20030814.083154.40b19dfb.html https://lists.exim.org/lurker/message/20030815.092719.8a26db10.html Solution :
Upgrade to Exim 4.21 or later, or apply the appropriate patches.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE : CVE-2003-0743
BID : 8518
Other references : OSVDB:10877
Nessus ID : 11828