An overflow vulnerability in the base64 decode function of Exim has been identified as CVE-2018-6789. This bug exists since the first commit of exim, hence ALL versions are affected. Patched version 4.90.1 is already released and we suggest to upgrade exim immediately. At least 400k servers are at risk due to the bug. The exploitation mechanism used to achieve pre-auth remote code execution is described in the following paragraphs. In order to leverage this one byte overflow, it is necessary to trick memory management mechanism.”]
Source: https://devco.re/blog/2018/03/06/exim-off-by-one-RCE-exploiting-CVE-2018-6789-en/

