Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
| Software | From | Fixed in |
|---|---|---|
| university_of_cambridge / exim | 3.36 | 3.36.x |
| university_of_cambridge / exim | 3.35 | 3.35.x |
| university_of_cambridge / exim | 4.10 | 4.10.x |