CVE-2001-0889

Exim 3.22 and earlier, in some configurations, does not properly verify the local part of an address when redirecting the address to a pipe, which could allow remote attackers to execute arbitrary commands via shell metacharacters.

Scoring

CVSS base score
0.03
EPSS probability
0.61%
Published
2002-06-25
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs