CVE-2019-13917

Name
CVE-2019-13917
Description
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch http://exim.org/static/doc/security/CVE-2019-13917.txt
Third Party Advisory https://www.debian.org/security/2019/dsa-4488
Third Party Advisory http://www.openwall.com/lists/oss-security/2019/07/26/5
Third Party Advisory https://seclists.org/bugtraq/2019/Jul/51
GENTOO https://security.gentoo.org/glsa/201909-06

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* exim >= 4.85 <= 4.92

Vulnerable and fixed packages

Source package Branch Version Maintainer Status