PT-2019-2908 · Exim+2 · Exim+2

Jeremy Harris

·

Publicado

2019-07-23

·

Atualizado

2024-06-15

·

CVE-2019-13917

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exim versions 4.85 through 4.92
Description The issue is related to errors in handling objects in memory, which can allow an attacker to elevate privileges and execute arbitrary code. This can occur in unusual configurations where the ${sort } expansion is used for items that can be controlled by an attacker, such as $local part or $domain.
Recommendations For Exim versions 4.85 through 4.92, update to version 4.92.1 to resolve the issue. As a temporary workaround, consider restricting the use of the ${sort } expansion for items that can be controlled by an attacker until the update is applied.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02878
CVE-2019-13917
DSA-4488-1
OPENSUSE-SU-2021:0753-1
OPENSUSE-SU-2024:10746-1
USN-4075-1

Produtos afetados

Exim
Suse
Ubuntu