CVE-2019-13917

Name
CVE-2019-13917
Description
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch http://exim.org/static/doc/security/CVE-2019-13917.txt
Third Party Advisory https://www.debian.org/security/2019/dsa-4488
Third Party Advisory http://www.openwall.com/lists/oss-security/2019/07/26/5
Third Party Advisory https://seclists.org/bugtraq/2019/Jul/51
GENTOO https://security.gentoo.org/glsa/201909-06

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* exim >= 4.85 <= 4.92

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
exim edge-community 4.92.1-r0 None fixed
exim edge-community 4.92-r0 None possibly vulnerable
exim edge-community 4.90.1-r0 None possibly vulnerable
exim edge-community 4.89.1-r0 None possibly vulnerable
exim edge-community 4.89-r7 None possibly vulnerable
exim edge-community 4.89-r5 None possibly vulnerable
exim 3.22-community 4.92.1-r0 None fixed
exim 3.22-community 4.92-r0 None possibly vulnerable
exim 3.22-community 4.90.1-r0 None possibly vulnerable
exim 3.22-community 4.89.1-r0 None possibly vulnerable
exim 3.22-community 4.89-r7 None possibly vulnerable
exim 3.22-community 4.89-r5 None possibly vulnerable
exim 3.21-community 4.92.1-r0 None fixed
exim 3.20-community 4.92.1-r0 None fixed
exim 3.19-community 4.92.1-r0 None fixed
exim 3.18-community 4.92.1-r0 None fixed
exim 3.17-community 4.92.1-r0 None fixed