The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Link | Tags |
---|---|
https://nostarttls.secvuln.info | tool signature |
https://www.exim.org | product |
https://www.exim.org/static/doc/security/CVE-2021-38371.txt | broken link vendor advisory |