CyberSec.Space Logo
Back to CVE Browser

CVE-2019-13917

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1920%
EPSS Percentile7.50th
PublishedJul 25, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

Affected Platforms (CPE)

πŸ“¦
Exim

Exim

>= 4.85 and <= 4.92
πŸ’»
Debian

Debian Linux

= 9.0
πŸ’»
Debian

Debian Linux

= 10.0

References & Advisories

Related Vulnerabilities