Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Henrik Krohns

#28548of 53,633
9Total CVSS
Vulnerabilities · 1
PT-2019-16009
9.0
2019-12-22
Exim · Sa-Exim · CVE-2019-19920
**Name of the Vulnerable Software and Affected Versions** sa-exim version 4.2.1 **Description** The issue allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on `eval` rather than direct parsing and/or use of the taint feature. **Recommendations** For sa-exim version 4.2.1, consider disabling the use of `eval` in Greylisting.pm or restrict access to writing .cf files and rules until a patch is available.