CVE Vulnerabilities

CVE-2019-13917

Published: Jul 25, 2019 | Modified: Sep 07, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
8.1 IMPORTANT
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

Affected Software

Name Vendor Start Version End Version
Exim Exim 4.85 (including) 4.92 (including)
Exim4 Ubuntu bionic *
Exim4 Ubuntu devel *
Exim4 Ubuntu disco *
Exim4 Ubuntu trusty *
Exim4 Ubuntu xenial *

References