Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
| Vendor | Product | Versions |
|---|---|---|
| exim | exim | 4.88, 4.88 through 4.99.4 (EXIM-Security-2026-06-22.1), 4.82 through 4.99.4 (EXIM-Security-2026-06-22.3) |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| debian | debian linux | cert_advisory | 90% |
| open source | exim | cert_advisory | 90% |
Updated affected versions to include 4.99.3, changed severity to HIGH, and provided a more detailed description of the vulnerability.
Initial creation