CVE-2016-9963: Canonical Ubuntu Linux
Medium severity, CVSS 5.9. EPSS: 3.1% chance of exploitation in the next 30 days.
Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 16.10 only
- Debian Debian Linux: version 8.0 only
- Exim Exim: up to and including 4.87
Published 2017-02-01. Last modified 2026-06-17.