Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
Weaknesses in this category are related to errors in the management of cryptographic keys.
Link | Tags |
---|---|
http://www.debian.org/security/2016/dsa-3747 | third party advisory vendor advisory |
http://www.exim.org/static/doc/CVE-2016-9963.txt | mitigation vendor advisory |
http://www.ubuntu.com/usn/USN-3164-1 | third party advisory vendor advisory |
https://bugs.exim.org/show_bug.cgi?id=1996 | issue tracking vendor advisory mitigation |
http://www.securitytracker.com/id/1037484 | vdb entry third party advisory |
http://www.securityfocus.com/bid/94947 | vdb entry third party advisory |