PT-2019-2908 · Exim+2 · Exim+2

Jeremy Harris

·

Published

2019-07-23

·

Updated

2024-06-15

·

CVE-2019-13917

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exim versions 4.85 through 4.92
Description The issue is related to errors in handling objects in memory, which can allow an attacker to elevate privileges and execute arbitrary code. This can occur in unusual configurations where the ${sort } expansion is used for items that can be controlled by an attacker, such as $local part or $domain.
Recommendations For Exim versions 4.85 through 4.92, update to version 4.92.1 to resolve the issue. As a temporary workaround, consider restricting the use of the ${sort } expansion for items that can be controlled by an attacker until the update is applied.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02878
CVE-2019-13917
DSA-4488-1
OPENSUSE-SU-2021:0753-1
OPENSUSE-SU-2024:10746-1
USN-4075-1

Affected Products

Exim
Suse
Ubuntu