CVE-2019-16928
Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
Affected Platforms (CPE)
📦
Exim
Exim
>= 4.92 and <= 4.92.2💻
Canonical
Ubuntu Linux
= 19.04💻
Debian
Debian Linux
= 10.0💻
Fedoraproject
Fedora
= 29💻
Fedoraproject
Fedora
= 30💻
Fedoraproject
