CVE-2025-26794

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.
Configurations

No configuration.

History

22 Feb 2025, 01:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/02/21/4 -
  • () http://www.openwall.com/lists/oss-security/2025/02/21/5 -

21 Feb 2025, 19:15

Type Values Removed Values Added
Summary
  • (es) Exim 4.98 anterior a la versíon 4.98.1 permite una inyección SQL remota cuando se usan serialización de ETRN con la tabla hints en SQLite.
References
  • () https://bugzilla.suse.com/show_bug.cgi?id=1237424 -
  • () https://code.exim.org/exim/exim/commit/bfe32b5c6ea033736a26da8421513206db9fe305 -
  • () https://github.com/Exim/exim/wiki/EximSecurity -
  • () https://github.com/NixOS/nixpkgs/pull/383926 -
  • () https://github.com/openbsd/ports/commit/584d2c49addce9ca0ae67882cc16969104d7f82d -

21 Feb 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-21 13:15

Updated : 2025-02-22 01:15


NVD link : CVE-2025-26794

Mitre link : CVE-2025-26794

CVE.ORG link : CVE-2025-26794


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')