CVE-2019-16928

Name
CVE-2019-16928
Description
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://git.exim.org/exim.git/commit/478effbfd9c3cc5a627fc671d4bf94d13670d65f
MISC https://lists.exim.org/lurker/message/20190927.032457.c1044d4c.en.html
MISC https://bugs.exim.org/show_bug.cgi?id=2449
mailing-list http://www.openwall.com/lists/oss-security/2019/09/28/1
mailing-list http://www.openwall.com/lists/oss-security/2019/09/28/2
mailing-list http://www.openwall.com/lists/oss-security/2019/09/28/3
vendor-advisory https://www.debian.org/security/2019/dsa-4536
vendor-advisory https://usn.ubuntu.com/4141-1/
mailing-list http://www.openwall.com/lists/oss-security/2019/09/28/4
mailing-list https://seclists.org/bugtraq/2019/Sep/60
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3TJW4HPYH3O5HZCWGD6NSHTEBTTAPDC/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UY6HPRW7MR3KBQ5JFHH6OXM7YCZBJCOB/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EED7HM3MFIBAP5OIMJAFJ35JAJABTVSC/
vendor-advisory https://security.gentoo.org/glsa/202003-47
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EED7HM3MFIBAP5OIMJAFJ35JAJABTVSC/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3TJW4HPYH3O5HZCWGD6NSHTEBTTAPDC/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UY6HPRW7MR3KBQ5JFHH6OXM7YCZBJCOB/
134c704f-9b21-4f2e-91b3-4a467353bcc0 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16928

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* exim >= 4.92 <= 4.92.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
exim edge-community 4.92.2-r1 None fixed
exim edge-community 4.92.2-r0 None possibly vulnerable
exim edge-community 4.92.1-r0 None possibly vulnerable
exim edge-community 4.92-r0 None possibly vulnerable
exim 3.22-community 4.92.2-r1 None fixed
exim 3.22-community 4.92.2-r0 None possibly vulnerable
exim 3.22-community 4.92.1-r0 None possibly vulnerable
exim 3.22-community 4.92-r0 None possibly vulnerable
exim 3.21-community 4.92.2-r1 None fixed
exim 3.20-community 4.92.2-r1 None fixed
exim 3.19-community 4.92.2-r1 None fixed
exim 3.18-community 4.92.2-r1 None fixed
exim 3.17-community 4.92.2-r1 None fixed