Exim 3.22 and earlier, in some configurations, does not properly verify the local part of an address when redirecting the address to a pipe, which could allow remote attackers to execute arbitrary commands via shell metacharacters.
| Software | From | Fixed in |
|---|---|---|
| university_of_cambridge / exim | - | 3.22.x |
| redhat / linux | - | - |