CVE-2014-2972: Exim

Medium severity, CVSS 4.6. EPSS: 0.5% chance of exploitation in the next 30 days.

expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.

Affected products

  • Exim Exim: up to and including 4.82.1; version 4.00 only; version 4.01 only; version 4.02 only; version 4.03 only; version 4.04 only; …

Published 2014-09-04. Last modified 2026-06-17.