Vulnerability resides with b64decode function in the SMTP listener. When the provided input is not a valid base64 string it consumes additional bytes while decoding which causes the one-byte heap overflow. An attacker could leverage the vulnerability by sending a crafted malicious request that causes the buffer overflow and it can use to execute the remote code. Users are advised to update their Exim server version to 4.90.1 or above. The vulnerability was tracked as CVE-2018-6789.”]
Source: https://gbhackers.com/exim-email-servers-vulnerability/

