Medium severity5.9NVD Advisory· Published Feb 1, 2017· Updated Jun 17, 2026
CVE-2016-9963
CVE-2016-9963
Description
Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.10:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- www.debian.org/security/2016/dsa-3747nvdThird Party Advisory
- www.exim.org/static/doc/CVE-2016-9963.txtnvdMitigationVendor Advisory
- www.securityfocus.com/bid/94947nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1037484nvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-3164-1nvdThird Party Advisory
- bugs.exim.org/show_bug.cginvdIssue TrackingMitigationVendor Advisory
News mentions
0No linked articles in our index yet.