The 2018 Pwnie Nominee For Best Server-Side Bug

Exim Off-by-one RCE

Credit: Meh Chang

Remotely owning mailservers is what old school Unix hacking was always about. Meh Change showed us how it was done this year by triggering one byte overflows, making fake chunk headers, extending chunks, freeing chunks, overwriting next pointers, and all the good stuff we know and love since the Vudo malloc tricks paper in Phrack showed us the ways of the dark side.

Exim Off-by-one RCE (CVE-2018-6789)